{"schema_version":"1.7.5","id":"CVE-2025-39757","published":"2025-09-11T16:52:26.900Z","modified":"2026-07-15T01:49:07.092013393Z","related":["ALSA-2025:17760","ALSA-2025:17776","ALSA-2025:18297","ALSA-2025:18298","SUSE-SU-2025:03600-1","SUSE-SU-2025:03614-1","SUSE-SU-2025:03634-1","SUSE-SU-2025:20851-1","SUSE-SU-2025:20861-1","SUSE-SU-2025:20870-1","SUSE-SU-2025:20898-1","SUSE-SU-2025:21074-1","SUSE-SU-2025:21139-1","SUSE-SU-2025:21179-1","SUSE-SU-2025:3751-1","SUSE-SU-2025:4057-1","SUSE-SU-2025:4132-1","SUSE-SU-2025:4141-1","SUSE-SU-2026:20560-1","openSUSE-SU-2025:20081-1"],"summary":"ALSA: usb-audio: Validate UAC3 cluster segment descriptors","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: Validate UAC3 cluster segment descriptors\n\nUAC3 class segment descriptors need to be verified whether their sizes\nmatch with the declared lengths and whether they fit with the\nallocated buffer sizes, too.  Otherwise malicious firmware may lead to\nthe unexpected OOB accesses.","affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"11785ef53228d23ec386f5fe4a34601536f0c891"},{"fixed":"799c06ad4c9c790c265e8b6b94947213f1fb389c"},{"fixed":"786571b10b1ae6d90e1242848ce78ee7e1d493c4"},{"fixed":"275e37532e8ebe25e8a4069b2d9f955bfd202a46"},{"fixed":"47ab3d820cb0a502bd0074f83bb3cf7ab5d79902"},{"fixed":"1034719fdefd26caeec0a44a868bb5a412c2c1a5"},{"fixed":"ae17b3b5e753efc239421d186cd1ff06e5ac296e"},{"fixed":"dfdcbcde5c20df878178245d4449feada7d5b201"},{"fixed":"7ef3fd250f84494fb2f7871f357808edaa1fc6ce"},{"fixed":"ecfd41166b72b67d3bdeb88d224ff445f6163869"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-39757.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.19.0"},{"fixed":"5.4.297"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.5.0"},{"fixed":"5.10.241"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.190"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.149"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.103"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.43"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.15.11"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.16.0"},{"fixed":"6.16.2"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-39757.json"}}],"references":[{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-032379.html"},{"type":"WEB","url":"https://git.kernel.org/stable/c/1034719fdefd26caeec0a44a868bb5a412c2c1a5"},{"type":"WEB","url":"https://git.kernel.org/stable/c/275e37532e8ebe25e8a4069b2d9f955bfd202a46"},{"type":"WEB","url":"https://git.kernel.org/stable/c/47ab3d820cb0a502bd0074f83bb3cf7ab5d79902"},{"type":"WEB","url":"https://git.kernel.org/stable/c/786571b10b1ae6d90e1242848ce78ee7e1d493c4"},{"type":"WEB","url":"https://git.kernel.org/stable/c/799c06ad4c9c790c265e8b6b94947213f1fb389c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/7ef3fd250f84494fb2f7871f357808edaa1fc6ce"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ae17b3b5e753efc239421d186cd1ff06e5ac296e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/dfdcbcde5c20df878178245d4449feada7d5b201"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ecfd41166b72b67d3bdeb88d224ff445f6163869"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/39xxx/CVE-2025-39757.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-39757"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/39xxx/CVE-2025-39757.json"}}