CVE-2025-38729
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-38729 is an out-of-bounds write vulnerability in the Linux kernel's ALSA (Advanced Linux Sound Architecture) USB audio subsystem, specifically in the handling of UAC3 (USB Audio Class 3) power domain descriptors. The flaw arises because the variable bLength field of UAC3 power domain descriptors is not validated, allowing malicious or malformed USB device firmware to trigger unexpected out-of-bounds memory accesses. It affects Linux kernel versions from 4.17 through multiple stable branches, with fixed versions available across all affected series. The vulnerability was published on September 4, 2025, and carries a CVSS v3.1 base score of 7.8 (High) (Red Hat CVE, Feedly).

Technical details

The root cause is classified as CWE-787 (Out-of-bounds Write): the Linux kernel's usb-audio driver processes UAC3 power domain descriptors without validating the variable-length bLength field, unlike other descriptor types that already perform such checks. An attacker with physical or logical access to connect a malicious USB audio device — or one with modified firmware — can cause the kernel to read or write beyond the intended memory buffer during descriptor parsing. This requires only local access with low privileges (e.g., the ability to plug in a USB device), and no user interaction beyond device connection is needed. No public proof-of-concept exploit code has been identified (Red Hat CVE, Feedly).

Impact

Successful exploitation can lead to privilege escalation, system crashes (denial of service), memory integrity compromise, and unauthorized disclosure of kernel memory contents. A local attacker with low privileges who can connect a malicious USB audio device may be able to escalate to root-level access or destabilize the system. The scope is limited to the affected host, but kernel-level compromise could enable further lateral movement within a multi-tenant or shared environment (Feedly, Red Hat CVE).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of this report. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.033%, reflecting a low probability of near-term exploitation. Exploitation requires physical or privileged logical access to connect a crafted USB audio device, which limits the practical attack surface (Feedly).

Mitigation and workarounds

The Linux kernel project has released patches across all affected stable branches. Administrators should upgrade to the following fixed versions or later: 5.4.297, 5.10.241, 5.15.190, 6.1.149, 6.6.103, 6.12.43, 6.15.11, 6.16.2, or 6.17-rc2. As a compensating control, organizations should implement physical USB port restrictions to prevent unauthorized device connections on sensitive systems. Red Hat has issued errata (e.g., RHSA-2025:21760, RHSA-2025:22006, RHSA-2025:22066, RHSA-2025:22072, RHSA-2025:22087, RHSA-2025:22095, RHSA-2025:23445, RHSA-2025:23947, RHSA-2025:23960) and Debian has issued DSA-6009-1 for affected distributions (Red Hat CVE, Red Hat Errata, Kernel Patches).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-74730CRITICAL9.8
  • Linux Kernel logoLinux Kernel
  • linux
NoYesAug 22, 2026
CVE-2026-74733HIGH7.8
  • Linux Kernel logoLinux Kernel
  • kernel-64k-debug-devel-matched
NoYesAug 22, 2026
CVE-2026-74726HIGH7.3
  • Linux Kernel logoLinux Kernel
  • kernel
NoYesAug 22, 2026
CVE-2026-74732MEDIUM5.5
  • Linux Kernel logoLinux Kernel
  • kernel-selftests-internal
NoYesAug 22, 2026
CVE-2026-74728NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug-modules-core
NoNoAug 22, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management