In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: Validate UAC3 power domain descriptors, too
UAC3 power domain descriptors need to be verified with its variable
bLength for avoiding the unexpected OOB accesses by malicious
firmware, too.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
08 Jan 2026, 17:31
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.17:rc1:*:*:*:*:*:* |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
| CWE | CWE-787 | |
| First Time |
Linux
Debian Debian debian Linux Linux linux Kernel |
|
| References | () https://git.kernel.org/stable/c/07c8d78dbb5e0ff8b23f7fd69cd1d4e2ba22b3dc - Patch | |
| References | () https://git.kernel.org/stable/c/1666207ba0a5973735ef010812536adde6174e81 - Patch | |
| References | () https://git.kernel.org/stable/c/29b415ec09f5b9d1dfa2423b826725a8c8796b9a - Patch | |
| References | () https://git.kernel.org/stable/c/40714daf4d0448e1692c78563faf0ed0f9d9b5c7 - Patch | |
| References | () https://git.kernel.org/stable/c/452ad54f432675982cc0d6eb6c40a6c86ac61dbd - Patch | |
| References | () https://git.kernel.org/stable/c/cd08d390d15b204cac1d3174f5f149a20c52e61a - Patch | |
| References | () https://git.kernel.org/stable/c/d832ccbc301fbd9e5a1d691bdcf461cdb514595f - Patch | |
| References | () https://git.kernel.org/stable/c/ebc9e06b6ea978a20abf9b87d41afc51b2d745ac - Patch | |
| References | () https://git.kernel.org/stable/c/f03418bb9d542f44df78eec2eff4ac83c0a8ac0d - Patch | |
| References | () https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html - Third Party Advisory, Mailing List | |
| References | () https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html - Third Party Advisory, Mailing List |
03 Nov 2025, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
04 Sep 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-09-04 16:15
Updated : 2026-01-08 17:31
NVD link : CVE-2025-38729
Mitre link : CVE-2025-38729
CVE.ORG link : CVE-2025-38729
JSON object : View
Products Affected
debian
- debian_linux
linux
- linux_kernel
CWE
CWE-787
Out-of-bounds Write
