Vulnerability in Linux Kernel Affecting ALSA USB Audio Components
CVE-2025-38729

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
4 September 2025

What is CVE-2025-38729?

The vulnerability in the Linux kernel pertains to the Advanced Linux Sound Architecture (ALSA) subsystem, specifically concerning UAC3 power domain descriptors. Without proper validation of the bLength variable in these descriptors, the system is susceptible to out-of-bounds (OOB) accesses, which could potentially be exploited by malicious firmware. This flaw emphasizes the need for stringent checks and validations in the firmware to ensure robust security, preventing unexpected behavior and vulnerabilities in audio handling.

Affected Version(s)

Linux 9a2fe9b801f585baccf8352d82839dcd54b300cf < 1666207ba0a5973735ef010812536adde6174e81

Linux 9a2fe9b801f585baccf8352d82839dcd54b300cf

Linux 9a2fe9b801f585baccf8352d82839dcd54b300cf

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-38729 : Vulnerability in Linux Kernel Affecting ALSA USB Audio Components