Executive brief
The Linux kernel USB-audio driver fails to validate the bLength field of descriptors while traversing clock sources. A local attacker can provide a bogus descriptor with a shorter-than-expected length to trigger an out-of-bounds read, potentially leading to sensitive information disclosure or a system crash.
Affected products
- Linux Linux Kernel up to (excluding) 5.4.287, 5.5 to (excluding) 5.10.231, 5.11 to (excluding) 5.15.174, 5.16 to (excluding) 6.1.120, 6.2 to (excluding) 6.6.64, 6.7 to (excluding) 6.11.11, 6.12 to (excluding) 6.12.2
- Debian Debian Linux 11.0
Timeline
- 2025-01-07: disclosed: Initial NIST analysis and CVE publication.
- 2025-04-09: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog.
- 2025-04-09: exploited: Reported as exploited in the wild.