CVE-2025-39757
ALSA: usb-audio: Validate UAC3 cluster segment descriptors
Description
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Validate UAC3 cluster segment descriptors UAC3 class segment descriptors need to be verified whether their sizes match with the declared lengths and whether they fit with the allocated buffer sizes, too. Otherwise malicious firmware may lead to the unexpected OOB accesses.
INFO
Published Date :
Sept. 11, 2025, 5:15 p.m.
Last Modified :
Sept. 11, 2025, 5:15 p.m.
Remotely Exploit :
No
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Solution
- Apply Linux kernel updates.
- Validate descriptor sizes against declared lengths.
- Ensure descriptors fit allocated buffer sizes.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2025-39757
.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2025-39757
is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2025-39757
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2025-39757
vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2025-39757
vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Sep. 11, 2025
Action Type Old Value New Value Added Description In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Validate UAC3 cluster segment descriptors UAC3 class segment descriptors need to be verified whether their sizes match with the declared lengths and whether they fit with the allocated buffer sizes, too. Otherwise malicious firmware may lead to the unexpected OOB accesses. Added Reference https://git.kernel.org/stable/c/1034719fdefd26caeec0a44a868bb5a412c2c1a5 Added Reference https://git.kernel.org/stable/c/275e37532e8ebe25e8a4069b2d9f955bfd202a46 Added Reference https://git.kernel.org/stable/c/47ab3d820cb0a502bd0074f83bb3cf7ab5d79902 Added Reference https://git.kernel.org/stable/c/786571b10b1ae6d90e1242848ce78ee7e1d493c4 Added Reference https://git.kernel.org/stable/c/799c06ad4c9c790c265e8b6b94947213f1fb389c Added Reference https://git.kernel.org/stable/c/7ef3fd250f84494fb2f7871f357808edaa1fc6ce Added Reference https://git.kernel.org/stable/c/ae17b3b5e753efc239421d186cd1ff06e5ac296e Added Reference https://git.kernel.org/stable/c/dfdcbcde5c20df878178245d4449feada7d5b201 Added Reference https://git.kernel.org/stable/c/ecfd41166b72b67d3bdeb88d224ff445f6163869