CVE-2025-38249 | Linux Kernel up to 6.1.142/6.6.95/6.12.35/6.15.4/6.16-rc3 ALSA snd_usb_get_audioformat_uac3 out-of-bounds (EUVD-2025-20812 / Nessus ID 265984)
A vulnerability described as problematic has been identified in Linux Kernel up to 6.1.142/6.6.95/6.12.35/6.15.4/6.16-rc3. Impacted is the function snd_usb_get_audioformat_uac3 of the component ALSA. Such manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2025-38249. The attack can only be initiated within the local network. No exploit exists.
Upgrading the affected component is recommended.