Executive brief
A vulnerability in the Linux kernel's USB audio driver could allow a malicious USB device to crash the system or potentially gain unauthorized access to memory. This occurs when the system processes specially crafted 'power domain' information from a USB Audio Class 3.0 device. An attacker with physical access to a USB port or the ability to redirect a USB device to a vulnerable system could exploit this flaw to disrupt operations or compromise data integrity.
Technical details
An out-of-bounds (OOB) access vulnerability exists in the Linux kernel's ALSA (Advanced Linux Sound Architecture) subsystem, specifically within the usb-audio driver's handling of USB Audio Device Class 3.0 (UAC3) descriptors. The root cause is a lack of validation for the 'bLength' variable in UAC3 power domain descriptors. A malicious USB device or firmware can provide a crafted descriptor that causes the kernel to perform OOB reads or writes during descriptor parsing in 'sound/usb/validate.c'. This can be exploited by an attacker with local access or physical access to plug in a malicious device, potentially leading to a system crash (DoS) or local privilege escalation. Patches have been released across multiple stable kernel branches.
Affected products
- Linux Linux Kernel 4.17 to 5.4.297, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2
Timeline
- 2025-08-14: disclosed: Initial patch submitted by Takashi Iwai
- 2025-08-28: patched: Patch committed to stable kernel trees
- 2025-09-04: advisory: CVE-2025-38729 published
References
- https://git.kernel.org/stable/c/07c8d78dbb5e0ff8b23f7fd69cd1d4e2ba22b3dc
- https://git.kernel.org/stable/c/1666207ba0a5973735ef010812536adde6174e81
- https://git.kernel.org/stable/c/29b415ec09f5b9d1dfa2423b826725a8c8796b9a
- https://git.kernel.org/stable/c/40714daf4d0448e1692c78563faf0ed0f9d9b5c7
- https://git.kernel.org/stable/c/452ad54f432675982cc0d6eb6c40a6c86ac61dbd
- https://git.kernel.org/stable/c/cd08d390d15b204cac1d3174f5f149a20c52e61a
- https://git.kernel.org/stable/c/d832ccbc301fbd9e5a1d691bdcf461cdb514595f