CVE Database
/

CVE-2025-38729

Back to search

CVE-2025-38729

Published: Sep 4, 2025

Modified: May 12, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Validate UAC3 power domain descriptors, too UAC3 power domain descriptors need to be verified with its variable bLength for avoiding the unexpected OOB accesses by malicious firmware, too.

VendorProductVersions

Linux

Linux

affected
9a2fe9b801f585baccf8352d82839dcd54b300cf - < 1666207ba0a5973735ef010812536adde6174e81
affected
9a2fe9b801f585baccf8352d82839dcd54b300cf - < ebc9e06b6ea978a20abf9b87d41afc51b2d745ac
affected
9a2fe9b801f585baccf8352d82839dcd54b300cf - < f03418bb9d542f44df78eec2eff4ac83c0a8ac0d
affected
9a2fe9b801f585baccf8352d82839dcd54b300cf - < 40714daf4d0448e1692c78563faf0ed0f9d9b5c7
affected
9a2fe9b801f585baccf8352d82839dcd54b300cf - < 07c8d78dbb5e0ff8b23f7fd69cd1d4e2ba22b3dc

+4 more versions

Linux

Linux

affected
4.17
unaffected
0 - < 4.17
unaffected
5.4.297 - <= 5.4.*
unaffected
5.10.241 - <= 5.10.*
unaffected
5.15.190 - <= 5.15.*

+6 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now