CVE-2025-38729
Not scored
ALSA: usb-audio: Validate UAC3 power domain descriptors, too
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Validate UAC3 power domain descriptors, too UAC3 power domain descriptors need to be verified with its variable bLength for avoiding the unexpected OOB accesses by malicious firmware, too.
Exploit probability
0.2%
Published
September 4, 2025
Required by
Not available
Last source change
July 15, 2026
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2025-38729
View original source
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Validate UAC3 power domain descriptors, too UAC3 power domain descriptors need to be verified with its variable bLength for avoiding the unexpected OOB accesses by malicious firmware, too.
05 / REFERENCES
Further evidence
- https://cert-portal.siemens.com/productcert/html/ssa-032379.html
- https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
- https://git.kernel.org/stable/c/07c8d78dbb5e0ff8b23f7fd69cd1d4e2ba22b3dc
- https://git.kernel.org/stable/c/1666207ba0a5973735ef010812536adde6174e81
- https://git.kernel.org/stable/c/29b415ec09f5b9d1dfa2423b826725a8c8796b9a
- https://git.kernel.org/stable/c/40714daf4d0448e1692c78563faf0ed0f9d9b5c7
- https://git.kernel.org/stable/c/452ad54f432675982cc0d6eb6c40a6c86ac61dbd
- https://git.kernel.org/stable/c/cd08d390d15b204cac1d3174f5f149a20c52e61a
- https://git.kernel.org/stable/c/d832ccbc301fbd9e5a1d691bdcf461cdb514595f
- https://git.kernel.org/stable/c/ebc9e06b6ea978a20abf9b87d41afc51b2d745ac
- https://git.kernel.org/stable/c/f03418bb9d542f44df78eec2eff4ac83c0a8ac0d
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38729.json
- https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
- https://nvd.nist.gov/vuln/detail/CVE-2025-38729