CVE-2025-38249

Updated: 2026-02-08 03:59:12.176906

Description:

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out-of-bounds read in snd_usb_get_audioformat_uac3() In snd_usb_get_audioformat_uac3(), the length value returned from snd_usb_ctl_msg() is used directly for memory allocation without validation. This length is controlled by the USB device. The allocated buffer is cast to a uac3_cluster_header_descriptor and its fields are accessed without verifying that the buffer is large enough. If the device returns a smaller than expected length, this leads to an out-of-bounds read. Add a length check to ensure the buffer is large enough for uac3_cluster_header_descriptor.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.1

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 7.1 HIGH Released CLSA-2026:1768663754 2026-01-17 19:47:21
CentOS 8.4 ELS kernel 4.18.0 7.1 HIGH Released CLSA-2026:1768774361 2026-01-19 09:45:22
CentOS 8.5 ELS kernel 4.18.0 7.1 HIGH Released CLSA-2026:1768775579 2026-01-19 09:45:23
CentOS Stream 8 ELS kernel 4.18.0 7.1 HIGH Released CLSA-2026:1770032032 2026-02-02 15:17:28
Oracle Linux 7 ELS kernel 3.10.0 7.1 HIGH Needs Triage 2025-12-28 19:15:52
Oracle Linux 7 ELS kernel-uek 5.4.17 7.1 HIGH Released CLSA-2025:1764085382 2025-11-25 20:35:52
TuxCare 9.6 ESU kernel 5.14.0 7.1 HIGH In Testing 2026-02-05 12:53:16
Ubuntu 20.04 ELS linux 5.4.0 7.1 HIGH In Testing 2026-02-03 16:03:14