
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-39757 is a vulnerability discovered in the Linux kernel's ALSA USB audio subsystem, specifically affecting the UAC3 cluster segment descriptors validation. The vulnerability was disclosed on September 11, 2025, and affects the Linux kernel's audio handling capabilities (NVD).
The vulnerability involves insufficient validation of UAC3 class segment descriptors in the USB audio subsystem. Specifically, the system fails to properly verify whether the sizes match with declared lengths and allocated buffer sizes, which could lead to out-of-bounds (OOB) accesses (NVD).
The vulnerability could allow malicious firmware to trigger unexpected out-of-bounds accesses in the system's memory, potentially compromising system security and stability (NVD).
Multiple Linux distributions have marked this vulnerability for patching, with Ubuntu classifying it as having medium priority. Various kernel versions across different distributions are being updated to address this vulnerability (Ubuntu).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."