CVE-2025-38729

Source
https://cve.org/CVERecord?id=CVE-2025-38729
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38729.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-38729
Downstream
Related
Published
2025-09-04T15:33:26.896Z
Modified
2026-05-28T03:55:02.543854086Z
Summary
ALSA: usb-audio: Validate UAC3 power domain descriptors, too
Details

In the Linux kernel, the following vulnerability has been resolved:

ALSA: usb-audio: Validate UAC3 power domain descriptors, too

UAC3 power domain descriptors need to be verified with its variable bLength for avoiding the unexpected OOB accesses by malicious firmware, too.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38729.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
9a2fe9b801f585baccf8352d82839dcd54b300cf
Fixed
1666207ba0a5973735ef010812536adde6174e81
Fixed
ebc9e06b6ea978a20abf9b87d41afc51b2d745ac
Fixed
f03418bb9d542f44df78eec2eff4ac83c0a8ac0d
Fixed
40714daf4d0448e1692c78563faf0ed0f9d9b5c7
Fixed
07c8d78dbb5e0ff8b23f7fd69cd1d4e2ba22b3dc
Fixed
cd08d390d15b204cac1d3174f5f149a20c52e61a
Fixed
29b415ec09f5b9d1dfa2423b826725a8c8796b9a
Fixed
452ad54f432675982cc0d6eb6c40a6c86ac61dbd
Fixed
d832ccbc301fbd9e5a1d691bdcf461cdb514595f

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38729.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.17.0
Fixed
5.4.297
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.241
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.190
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.149
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.103
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.43
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.15.11
Type
ECOSYSTEM
Events
Introduced
6.16.0
Fixed
6.16.2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38729.json"