You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
ALSA: usb-audio: Validate UAC3 power domain descriptors, too
jira LE-4395
cve CVE-2025-38729
Rebuild_History Non-Buildable kernel-6.12.0-55.39.1.el10_0
commit-author Takashi Iwai <tiwai@suse.de>
commit d832ccb
UAC3 power domain descriptors need to be verified with its variable
bLength for avoiding the unexpected OOB accesses by malicious
firmware, too.
Fixes: 9a2fe9b ("ALSA: usb: initial USB Audio Device Class 3.0 support")
Reported-and-tested-by: Youngjun Lee <yjjuny.lee@samsung.com>
Cc: <stable@vger.kernel.org>
Link: https://patch.msgid.link/20250814081245.8902-1-tiwai@suse.de
Signed-off-by: Takashi Iwai <tiwai@suse.de>
(cherry picked from commit d832ccb)
Signed-off-by: Jonathan Maple <jmaple@ciq.com>
0 commit comments