CVE-2025-39757

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-39757
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-39757.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-39757
Downstream
Related
Published
2025-09-11T16:52:26.900Z
Modified
2025-11-28T02:34:05.385979Z
Summary
ALSA: usb-audio: Validate UAC3 cluster segment descriptors
Details

In the Linux kernel, the following vulnerability has been resolved:

ALSA: usb-audio: Validate UAC3 cluster segment descriptors

UAC3 class segment descriptors need to be verified whether their sizes match with the declared lengths and whether they fit with the allocated buffer sizes, too. Otherwise malicious firmware may lead to the unexpected OOB accesses.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/39xxx/CVE-2025-39757.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
11785ef53228d23ec386f5fe4a34601536f0c891
Fixed
799c06ad4c9c790c265e8b6b94947213f1fb389c
Fixed
786571b10b1ae6d90e1242848ce78ee7e1d493c4
Fixed
275e37532e8ebe25e8a4069b2d9f955bfd202a46
Fixed
47ab3d820cb0a502bd0074f83bb3cf7ab5d79902
Fixed
1034719fdefd26caeec0a44a868bb5a412c2c1a5
Fixed
ae17b3b5e753efc239421d186cd1ff06e5ac296e
Fixed
dfdcbcde5c20df878178245d4449feada7d5b201
Fixed
7ef3fd250f84494fb2f7871f357808edaa1fc6ce
Fixed
ecfd41166b72b67d3bdeb88d224ff445f6163869

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.19.0
Fixed
5.4.297
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.241
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.190
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.149
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.103
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.43
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.15.11
Type
ECOSYSTEM
Events
Introduced
6.16.0
Fixed
6.16.2