Home

Description

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Validate UAC3 power domain descriptors, too UAC3 power domain descriptors need to be verified with its variable bLength for avoiding the unexpected OOB accesses by malicious firmware, too.

PUBLISHED Reserved 2025-04-16 | Published 2025-09-04 | Updated 2025-09-29 | Assigner Linux

Product status

Default status
unaffected

9a2fe9b801f585baccf8352d82839dcd54b300cf (git) before 1666207ba0a5973735ef010812536adde6174e81
affected

9a2fe9b801f585baccf8352d82839dcd54b300cf (git) before ebc9e06b6ea978a20abf9b87d41afc51b2d745ac
affected

9a2fe9b801f585baccf8352d82839dcd54b300cf (git) before f03418bb9d542f44df78eec2eff4ac83c0a8ac0d
affected

9a2fe9b801f585baccf8352d82839dcd54b300cf (git) before 40714daf4d0448e1692c78563faf0ed0f9d9b5c7
affected

9a2fe9b801f585baccf8352d82839dcd54b300cf (git) before 07c8d78dbb5e0ff8b23f7fd69cd1d4e2ba22b3dc
affected

9a2fe9b801f585baccf8352d82839dcd54b300cf (git) before cd08d390d15b204cac1d3174f5f149a20c52e61a
affected

9a2fe9b801f585baccf8352d82839dcd54b300cf (git) before 29b415ec09f5b9d1dfa2423b826725a8c8796b9a
affected

9a2fe9b801f585baccf8352d82839dcd54b300cf (git) before 452ad54f432675982cc0d6eb6c40a6c86ac61dbd
affected

9a2fe9b801f585baccf8352d82839dcd54b300cf (git) before d832ccbc301fbd9e5a1d691bdcf461cdb514595f
affected

Default status
affected

4.17
affected

Any version before 4.17
unaffected

5.4.297 (semver)
unaffected

5.10.241 (semver)
unaffected

5.15.190 (semver)
unaffected

6.1.149 (semver)
unaffected

6.6.103 (semver)
unaffected

6.12.43 (semver)
unaffected

6.15.11 (semver)
unaffected

6.16.2 (semver)
unaffected

6.17 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/1666207ba0a5973735ef010812536adde6174e81

git.kernel.org/...c/ebc9e06b6ea978a20abf9b87d41afc51b2d745ac

git.kernel.org/...c/f03418bb9d542f44df78eec2eff4ac83c0a8ac0d

git.kernel.org/...c/40714daf4d0448e1692c78563faf0ed0f9d9b5c7

git.kernel.org/...c/07c8d78dbb5e0ff8b23f7fd69cd1d4e2ba22b3dc

git.kernel.org/...c/cd08d390d15b204cac1d3174f5f149a20c52e61a

git.kernel.org/...c/29b415ec09f5b9d1dfa2423b826725a8c8796b9a

git.kernel.org/...c/452ad54f432675982cc0d6eb6c40a6c86ac61dbd

git.kernel.org/...c/d832ccbc301fbd9e5a1d691bdcf461cdb514595f

cve.org (CVE-2025-38729)

nvd.nist.gov (CVE-2025-38729)

Download JSON