CVE-2025-39757 | ALSA: usb-audio: Validate UAC3 cluster segment descriptors

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Validate UAC3 cluster segment descriptors UAC3 class segment descriptors need to be verified whether their sizes match with the declared lengths and whether they fit with the allocated buffer sizes, too. Otherwise malicious firmware may lead to the unexpected OOB accesses.

Published: 2025-09-11 Last update: 2026-05-12 Assigner: 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67

Conclusion & alert: CVE-2025-39757 is rated Low Risk (30.6/100): CVSS High severity, with low exploitation likelihood (EPSS 0.16%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2025-39757

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.03% 0.16% +0.13%
2 2025-09-12 0.03%

Full EPSS history (2 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2025-39757

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
7.1 3.1 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H Click to expand
Attack vector (AV:L)
They already need access on the box, or another person has to do something wrong; it’s not a remote drive-by.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:L)
A normal user session is enough; they don’t have to be admin.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
1.8 5.2 [email protected]

Weakness enumeration for CVE-2025-39757

GitHub Security Advisory for CVE-2025-39757

GHSA-jrpg-g4vf-p4hw · Severity: high — In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Validate...

OS Trackers for CVE-2025-39757

vendor priority summary link
debian not yet assigned CVE-2025-39757 not yet assigned priority: Debian including 2 source packages (linux, linux-6.1), 6 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 6. https://security-tracker.debian.org/tracker/CVE-2025-39757
redhat medium https://access.redhat.com/security/cve/CVE-2025-39757
suse medium CVE-2025-39757 severity moderate: SUSE including 546 source package names (2.1.3-6.80:kernel-default-base-6.4.0-35.1.21.12, 2.1.3-7.57:kernel-default-6.4.0-35.1, …), 1049 product×package rows across 203 product lines (Container suse/sl-micro/6.0/base-os-container, Container suse/sl-micro/6.0/kvm-os-container, … (203 product lines)): Fixed 765, Known Affected 231, Known Not Affected 32, First Fixed 21. https://www.suse.com/security/cve/CVE-2025-39757/
ubuntu medium CVE-2025-39757 medium priority: Ubuntu including 158 source packages (linux, linux-allwinner-5.19, …), 1414 status rows across 9 suites (bionic, focal, jammy, noble, plucky, questing, trusty, upstream, xenial): DNE 1017, ignored 176, released 150, not-affected 40, needed 28, needs-triage 2, pending 1. https://ubuntu.com/security/CVE-2025-39757

Affected software / configurations for CVE-2025-39757

Vendor Product Version Raw CPE
linux linux_kernel >= 4.19, < 5.4.297 cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
linux linux_kernel >= 5.5, < 5.10.241 cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
linux linux_kernel >= 5.11, < 5.15.190 cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
linux linux_kernel >= 5.16, < 6.1.149 cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
linux linux_kernel >= 6.2, < 6.6.103 cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
linux linux_kernel >= 6.7, < 6.12.43 cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
linux linux_kernel >= 6.13, < 6.15.11 cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
linux linux_kernel >= 6.16, < 6.16.2 cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
linux linux_kernel 6.17 cpe:2.3:o:linux:linux_kernel:6.17:rc1:*:*:*:*:*:*
debian debian_linux 11.0 cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

References for CVE-2025-39757

URL Tags
https://git.kernel.org/stable/c/1034719fdefd26caeec0a44a868bb5a412c2c1a5 Patch
https://git.kernel.org/stable/c/275e37532e8ebe25e8a4069b2d9f955bfd202a46 Patch
https://git.kernel.org/stable/c/47ab3d820cb0a502bd0074f83bb3cf7ab5d79902 Patch
https://git.kernel.org/stable/c/786571b10b1ae6d90e1242848ce78ee7e1d493c4 Patch
https://git.kernel.org/stable/c/799c06ad4c9c790c265e8b6b94947213f1fb389c Patch
https://git.kernel.org/stable/c/7ef3fd250f84494fb2f7871f357808edaa1fc6ce Patch
https://git.kernel.org/stable/c/ae17b3b5e753efc239421d186cd1ff06e5ac296e Patch
https://git.kernel.org/stable/c/dfdcbcde5c20df878178245d4449feada7d5b201 Patch
https://git.kernel.org/stable/c/ecfd41166b72b67d3bdeb88d224ff445f6163869 Patch
https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html Mailing List Third Party Advisory
https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html Mailing List Third Party Advisory
https://cert-portal.siemens.com/productcert/html/ssa-032379.html
cvelogic Threat Intelligence