In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Validate UAC3 cluster segment descriptors UAC3 class segment descriptors need to be verified whether their sizes match with the declared lengths and whether they fit with the allocated buffer sizes, too. Otherwise malicious firmware may lead to the unexpected OOB accesses.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2025091144-CVE-2025-39757-e212@gregkh/T
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:17760 https://access.redhat.com/errata/RHSA-2025:17760
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:17776 https://access.redhat.com/errata/RHSA-2025:17776
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:18298 https://access.redhat.com/errata/RHSA-2025:18298
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:18297 https://access.redhat.com/errata/RHSA-2025:18297
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:21118 https://access.redhat.com/errata/RHSA-2025:21118
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:21760 https://access.redhat.com/errata/RHSA-2025:21760
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2025:22006 https://access.redhat.com/errata/RHSA-2025:22006
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:22066 https://access.redhat.com/errata/RHSA-2025:22066
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2025:22072 https://access.redhat.com/errata/RHSA-2025:22072
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:22087 https://access.redhat.com/errata/RHSA-2025:22087
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2025:22095 https://access.redhat.com/errata/RHSA-2025:22095
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2025:22124 https://access.redhat.com/errata/RHSA-2025:22124