Junglewise Threat Intelligence

CVE-2025-38729: Linux Kernel ALSA out-of-bounds access in USB-Audio UAC3

CVE-2025-38729 · Severity: high · CVSS 7.8 · Published 2025-09-04

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's USB audio driver could allow a malicious USB device to crash the system or potentially gain unauthorized access to memory. This occurs when the system processes specially crafted 'power domain' information from a USB Audio Class 3.0 device. An attacker with physical access to a USB port or the ability to redirect a USB device to a vulnerable system could exploit this flaw to disrupt operations or compromise data integrity.

Technical details

An out-of-bounds (OOB) access vulnerability exists in the Linux kernel's ALSA (Advanced Linux Sound Architecture) subsystem, specifically within the usb-audio driver's handling of USB Audio Device Class 3.0 (UAC3) descriptors. The root cause is a lack of validation for the 'bLength' variable in UAC3 power domain descriptors. A malicious USB device or firmware can provide a crafted descriptor that causes the kernel to perform OOB reads or writes during descriptor parsing in 'sound/usb/validate.c'. This can be exploited by an attacker with local access or physical access to plug in a malicious device, potentially leading to a system crash (DoS) or local privilege escalation. Patches have been released across multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 4.17 to 5.4.297, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2

Timeline

  • 2025-08-14: disclosed: Initial patch submitted by Takashi Iwai
  • 2025-08-28: patched: Patch committed to stable kernel trees
  • 2025-09-04: advisory: CVE-2025-38729 published

References

Related threats