U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

CVE-2025-38729 Detail

Description

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Validate UAC3 power domain descriptors, too UAC3 power domain descriptors need to be verified with its variable bLength for avoiding the unexpected OOB accesses by malicious firmware, too.


Metrics

NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 4.0 Severity and Vector Strings:

NIST CVSS score
NIST: NVD
N/A
NVD assessment not yet provided.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [email protected].

URL Source(s) Tag(s)
https://git.kernel.org/stable/c/07c8d78dbb5e0ff8b23f7fd69cd1d4e2ba22b3dc kernel.org
https://git.kernel.org/stable/c/1666207ba0a5973735ef010812536adde6174e81 kernel.org
https://git.kernel.org/stable/c/29b415ec09f5b9d1dfa2423b826725a8c8796b9a kernel.org
https://git.kernel.org/stable/c/40714daf4d0448e1692c78563faf0ed0f9d9b5c7 kernel.org
https://git.kernel.org/stable/c/452ad54f432675982cc0d6eb6c40a6c86ac61dbd kernel.org
https://git.kernel.org/stable/c/cd08d390d15b204cac1d3174f5f149a20c52e61a kernel.org
https://git.kernel.org/stable/c/d832ccbc301fbd9e5a1d691bdcf461cdb514595f kernel.org
https://git.kernel.org/stable/c/ebc9e06b6ea978a20abf9b87d41afc51b2d745ac kernel.org
https://git.kernel.org/stable/c/f03418bb9d542f44df78eec2eff4ac83c0a8ac0d kernel.org

Weakness Enumeration

CWE-ID CWE Name Source

Change History

1 change records found show changes

Quick Info

CVE Dictionary Entry:
CVE-2025-38729
NVD Published Date:
09/04/2025
NVD Last Modified:
09/05/2025
Source:
kernel.org