In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: Validate UAC3 power domain descriptors, too
UAC3 power domain descriptors need to be verified with its variable bLength for avoiding the unexpected OOB accesses by malicious firmware, too.
[
{
"signature_version": "v1",
"id": "CVE-2025-38729-077b5645",
"digest": {
"threshold": 0.9,
"line_hashes": [
"165012268255961929549306168467633367466",
"244963346343475714955514532768670438499",
"8147523287340405975790421646443371184",
"96173901951775343969272340564745542935",
"334930895537073136651265259092039403210",
"222565941529267720815841124181036401036"
]
},
"deprecated": false,
"target": {
"file": "sound/usb/validate.c"
},
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@07c8d78dbb5e0ff8b23f7fd69cd1d4e2ba22b3dc"
},
{
"signature_version": "v1",
"id": "CVE-2025-38729-0952ba35",
"digest": {
"threshold": 0.9,
"line_hashes": [
"165012268255961929549306168467633367466",
"244963346343475714955514532768670438499",
"8147523287340405975790421646443371184",
"96173901951775343969272340564745542935",
"334930895537073136651265259092039403210",
"222565941529267720815841124181036401036"
]
},
"deprecated": false,
"target": {
"file": "sound/usb/validate.c"
},
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ebc9e06b6ea978a20abf9b87d41afc51b2d745ac"
},
{
"signature_version": "v1",
"id": "CVE-2025-38729-49d394a5",
"digest": {
"threshold": 0.9,
"line_hashes": [
"165012268255961929549306168467633367466",
"244963346343475714955514532768670438499",
"8147523287340405975790421646443371184",
"96173901951775343969272340564745542935",
"334930895537073136651265259092039403210",
"222565941529267720815841124181036401036"
]
},
"deprecated": false,
"target": {
"file": "sound/usb/validate.c"
},
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@452ad54f432675982cc0d6eb6c40a6c86ac61dbd"
},
{
"signature_version": "v1",
"id": "CVE-2025-38729-696b56bc",
"digest": {
"threshold": 0.9,
"line_hashes": [
"165012268255961929549306168467633367466",
"244963346343475714955514532768670438499",
"8147523287340405975790421646443371184",
"96173901951775343969272340564745542935",
"334930895537073136651265259092039403210",
"222565941529267720815841124181036401036"
]
},
"deprecated": false,
"target": {
"file": "sound/usb/validate.c"
},
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@cd08d390d15b204cac1d3174f5f149a20c52e61a"
},
{
"signature_version": "v1",
"id": "CVE-2025-38729-7c76bf32",
"digest": {
"threshold": 0.9,
"line_hashes": [
"165012268255961929549306168467633367466",
"244963346343475714955514532768670438499",
"8147523287340405975790421646443371184",
"96173901951775343969272340564745542935",
"334930895537073136651265259092039403210",
"222565941529267720815841124181036401036"
]
},
"deprecated": false,
"target": {
"file": "sound/usb/validate.c"
},
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1666207ba0a5973735ef010812536adde6174e81"
},
{
"signature_version": "v1",
"id": "CVE-2025-38729-9b8a9061",
"digest": {
"threshold": 0.9,
"line_hashes": [
"165012268255961929549306168467633367466",
"244963346343475714955514532768670438499",
"8147523287340405975790421646443371184",
"96173901951775343969272340564745542935",
"334930895537073136651265259092039403210",
"222565941529267720815841124181036401036"
]
},
"deprecated": false,
"target": {
"file": "sound/usb/validate.c"
},
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@d832ccbc301fbd9e5a1d691bdcf461cdb514595f"
},
{
"signature_version": "v1",
"id": "CVE-2025-38729-a1a13ba9",
"digest": {
"threshold": 0.9,
"line_hashes": [
"165012268255961929549306168467633367466",
"244963346343475714955514532768670438499",
"8147523287340405975790421646443371184",
"96173901951775343969272340564745542935",
"334930895537073136651265259092039403210",
"222565941529267720815841124181036401036"
]
},
"deprecated": false,
"target": {
"file": "sound/usb/validate.c"
},
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@29b415ec09f5b9d1dfa2423b826725a8c8796b9a"
},
{
"signature_version": "v1",
"id": "CVE-2025-38729-d0589619",
"digest": {
"threshold": 0.9,
"line_hashes": [
"165012268255961929549306168467633367466",
"244963346343475714955514532768670438499",
"8147523287340405975790421646443371184",
"96173901951775343969272340564745542935",
"334930895537073136651265259092039403210",
"222565941529267720815841124181036401036"
]
},
"deprecated": false,
"target": {
"file": "sound/usb/validate.c"
},
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@40714daf4d0448e1692c78563faf0ed0f9d9b5c7"
}
]