• Tenable
  • CVEs
  • Settings
    Links
    Tenable Cloud Tenable Community & Support Tenable University
    Severity
    Theme
  • Tenable
  • Plugins
  • Overview
  • Plugins Pipeline
  • Newest
  • Updated
  • Search
  • Nessus Families
  • WAS Families
  • NNM Families
  • Tenable OT Security Families
  • About Plugin Families
  • Release Notes
  • Audits
  • Overview
  • Newest
  • Updated
  • Search Audit Files
  • Search Items
  • References
  • Authorities
  • Documentation
  • Download All Audit Files
  • Indicators
  • Overview
  • Search
  • Indicators of Attack
  • Indicators of Exposure
  • Release Notes
  • CVEs
  • Overview
  • Newest
  • Updated
  • Search
  • Attack Path Techniques
  • Overview
  • Search
    • Links
    • Tenable Cloud
    • Tenable Community & Support
    • Tenable University
    • Settings
    • Severity
    • Theme
Detections
  • Plugins
  • Overview
  • Plugins Pipeline
  • Release Notes
  • Newest
  • Updated
  • Search
  • Nessus Families
  • WAS Families
  • NNM Families
  • Tenable OT Security Families
  • About Plugin Families
  • Audits
  • Overview
  • Newest
  • Updated
  • Search Audit Files
  • Search Items
  • References
  • Authorities
  • Documentation
  • Download All Audit Files
  • Indicators
  • Overview
  • Search
  • Indicators of Attack
  • Indicators of Exposure
  • Release Notes
Analytics
  • CVEs
  • Overview
  • Newest
  • Updated
  • Search
  • Attack Path Techniques
  • Overview
  • Search
  1. CVEs
  2. CVE-2025-38729
  1. CVEs

CVE-2025-38729

high
  • Information
  • CPEs
  • Plugins

Description

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Validate UAC3 power domain descriptors, too UAC3 power domain descriptors need to be verified with its variable bLength for avoiding the unexpected OOB accesses by malicious firmware, too.

References

  • Advisories
  • More

https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html

https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html

https://git.kernel.org/stable/c/f03418bb9d542f44df78eec2eff4ac83c0a8ac0d

https://git.kernel.org/stable/c/ebc9e06b6ea978a20abf9b87d41afc51b2d745ac

https://git.kernel.org/stable/c/d832ccbc301fbd9e5a1d691bdcf461cdb514595f

https://git.kernel.org/stable/c/cd08d390d15b204cac1d3174f5f149a20c52e61a

https://git.kernel.org/stable/c/452ad54f432675982cc0d6eb6c40a6c86ac61dbd

https://git.kernel.org/stable/c/40714daf4d0448e1692c78563faf0ed0f9d9b5c7

https://git.kernel.org/stable/c/29b415ec09f5b9d1dfa2423b826725a8c8796b9a

https://git.kernel.org/stable/c/1666207ba0a5973735ef010812536adde6174e81

https://git.kernel.org/stable/c/07c8d78dbb5e0ff8b23f7fd69cd1d4e2ba22b3dc

Details

Source: Mitre, NVD

Published: 2025-09-04

Updated: 2026-01-08

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00033

  • Tenable.com
  • Community & Support
  • Documentation
  • Education
  • © 2026 Tenable®, Inc. All Rights Reserved
  • Privacy Policy
  • Legal
  • 508 Compliance