
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-38729 is an out-of-bounds write vulnerability in the Linux kernel's ALSA (Advanced Linux Sound Architecture) USB audio subsystem, specifically in the handling of UAC3 (USB Audio Class 3) power domain descriptors. The flaw arises because the variable bLength field of UAC3 power domain descriptors is not validated, allowing malicious or malformed USB device firmware to trigger unexpected out-of-bounds memory accesses. It affects Linux kernel versions from 4.17 through multiple stable branches, with fixed versions available across all affected series. The vulnerability was published on September 4, 2025, and carries a CVSS v3.1 base score of 7.8 (High) (Red Hat CVE, Feedly).
The root cause is classified as CWE-787 (Out-of-bounds Write): the Linux kernel's usb-audio driver processes UAC3 power domain descriptors without validating the variable-length bLength field, unlike other descriptor types that already perform such checks. An attacker with physical or logical access to connect a malicious USB audio device — or one with modified firmware — can cause the kernel to read or write beyond the intended memory buffer during descriptor parsing. This requires only local access with low privileges (e.g., the ability to plug in a USB device), and no user interaction beyond device connection is needed. No public proof-of-concept exploit code has been identified (Red Hat CVE, Feedly).
Successful exploitation can lead to privilege escalation, system crashes (denial of service), memory integrity compromise, and unauthorized disclosure of kernel memory contents. A local attacker with low privileges who can connect a malicious USB audio device may be able to escalate to root-level access or destabilize the system. The scope is limited to the affected host, but kernel-level compromise could enable further lateral movement within a multi-tenant or shared environment (Feedly, Red Hat CVE).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of this report. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.033%, reflecting a low probability of near-term exploitation. Exploitation requires physical or privileged logical access to connect a crafted USB audio device, which limits the practical attack surface (Feedly).
The Linux kernel project has released patches across all affected stable branches. Administrators should upgrade to the following fixed versions or later: 5.4.297, 5.10.241, 5.15.190, 6.1.149, 6.6.103, 6.12.43, 6.15.11, 6.16.2, or 6.17-rc2. As a compensating control, organizations should implement physical USB port restrictions to prevent unauthorized device connections on sensitive systems. Red Hat has issued errata (e.g., RHSA-2025:21760, RHSA-2025:22006, RHSA-2025:22066, RHSA-2025:22072, RHSA-2025:22087, RHSA-2025:22095, RHSA-2025:23445, RHSA-2025:23947, RHSA-2025:23960) and Debian has issued DSA-6009-1 for affected distributions (Red Hat CVE, Red Hat Errata, Kernel Patches).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."