CVE-2025-38729
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Validate UAC3 power domain descriptors, too UAC3 power domain descriptors need to be verified with its variable bLength for avoiding the unexpected OOB accesses by…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.19%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Validate UAC3 power domain descriptors, too UAC3 power domain descriptors need to be verified with its variable bLength for avoiding the unexpected OOB accesses by malicious firmware, too.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.19% probability · 8th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- linux/linux kernel · debian/debian linux
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/07c8d78dbb5e0ff8b23f7fd69cd1d4e2ba22b3dcPatch
- https://git.kernel.org/stable/c/1666207ba0a5973735ef010812536adde6174e81Patch
- https://git.kernel.org/stable/c/29b415ec09f5b9d1dfa2423b826725a8c8796b9aPatch
- https://git.kernel.org/stable/c/40714daf4d0448e1692c78563faf0ed0f9d9b5c7Patch
- https://git.kernel.org/stable/c/452ad54f432675982cc0d6eb6c40a6c86ac61dbdPatch
- https://git.kernel.org/stable/c/cd08d390d15b204cac1d3174f5f149a20c52e61aPatch
- https://git.kernel.org/stable/c/d832ccbc301fbd9e5a1d691bdcf461cdb514595fPatch
- https://git.kernel.org/stable/c/ebc9e06b6ea978a20abf9b87d41afc51b2d745acPatch
- https://git.kernel.org/stable/c/f03418bb9d542f44df78eec2eff4ac83c0a8ac0dPatch
- https://lists.debian.org/debian-lts-announce/2025/10/msg00007.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.htmlMailing List, Third Party Advisory
- https://cert-portal.siemens.com/productcert/html/ssa-032379.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.