Description
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Validate UAC3 power domain descriptors, too UAC3 power domain descriptors need to be verified with its variable bLength for avoiding the unexpected OOB accesses by malicious firmware, too.
Product status
9a2fe9b801f585baccf8352d82839dcd54b300cf (git) before 1666207ba0a5973735ef010812536adde6174e81
9a2fe9b801f585baccf8352d82839dcd54b300cf (git) before ebc9e06b6ea978a20abf9b87d41afc51b2d745ac
9a2fe9b801f585baccf8352d82839dcd54b300cf (git) before f03418bb9d542f44df78eec2eff4ac83c0a8ac0d
9a2fe9b801f585baccf8352d82839dcd54b300cf (git) before 40714daf4d0448e1692c78563faf0ed0f9d9b5c7
9a2fe9b801f585baccf8352d82839dcd54b300cf (git) before 07c8d78dbb5e0ff8b23f7fd69cd1d4e2ba22b3dc
9a2fe9b801f585baccf8352d82839dcd54b300cf (git) before cd08d390d15b204cac1d3174f5f149a20c52e61a
9a2fe9b801f585baccf8352d82839dcd54b300cf (git) before 29b415ec09f5b9d1dfa2423b826725a8c8796b9a
9a2fe9b801f585baccf8352d82839dcd54b300cf (git) before 452ad54f432675982cc0d6eb6c40a6c86ac61dbd
9a2fe9b801f585baccf8352d82839dcd54b300cf (git) before d832ccbc301fbd9e5a1d691bdcf461cdb514595f
4.17
Any version before 4.17
5.4.297 (semver)
5.10.241 (semver)
5.15.190 (semver)
6.1.149 (semver)
6.6.103 (semver)
6.12.43 (semver)
6.15.11 (semver)
6.16.2 (semver)
6.17 (original_commit_for_fix)
References
git.kernel.org/...c/1666207ba0a5973735ef010812536adde6174e81
git.kernel.org/...c/ebc9e06b6ea978a20abf9b87d41afc51b2d745ac
git.kernel.org/...c/f03418bb9d542f44df78eec2eff4ac83c0a8ac0d
git.kernel.org/...c/40714daf4d0448e1692c78563faf0ed0f9d9b5c7
git.kernel.org/...c/07c8d78dbb5e0ff8b23f7fd69cd1d4e2ba22b3dc
git.kernel.org/...c/cd08d390d15b204cac1d3174f5f149a20c52e61a
git.kernel.org/...c/29b415ec09f5b9d1dfa2423b826725a8c8796b9a
git.kernel.org/...c/452ad54f432675982cc0d6eb6c40a6c86ac61dbd
git.kernel.org/...c/d832ccbc301fbd9e5a1d691bdcf461cdb514595f