CVE-2025-38729

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/09/2025
Last modified:
05/09/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ALSA: usb-audio: Validate UAC3 power domain descriptors, too<br /> <br /> UAC3 power domain descriptors need to be verified with its variable<br /> bLength for avoiding the unexpected OOB accesses by malicious<br /> firmware, too.

Impact