Back to search
CVE-2025-39757
Published: Sep 11, 2025
Modified: May 12, 2026
PUBLISHED
Description
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Validate UAC3 cluster segment descriptors UAC3 class segment descriptors need to be verified whether their sizes match with the declared lengths and whether they fit with the allocated buffer sizes, too. Otherwise malicious firmware may lead to the unexpected OOB accesses.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 11785ef53228d23ec386f5fe4a34601536f0c891 - < 799c06ad4c9c790c265e8b6b94947213f1fb389caffected 11785ef53228d23ec386f5fe4a34601536f0c891 - < 786571b10b1ae6d90e1242848ce78ee7e1d493c4affected 11785ef53228d23ec386f5fe4a34601536f0c891 - < 275e37532e8ebe25e8a4069b2d9f955bfd202a46affected 11785ef53228d23ec386f5fe4a34601536f0c891 - < 47ab3d820cb0a502bd0074f83bb3cf7ab5d79902affected 11785ef53228d23ec386f5fe4a34601536f0c891 - < 1034719fdefd26caeec0a44a868bb5a412c2c1a5+4 more versions |
Linux | Linux | affected 4.19unaffected 0 - < 4.19unaffected 5.4.297 - <= 5.4.*unaffected 5.10.241 - <= 5.10.*unaffected 5.15.190 - <= 5.15.*+6 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now