In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Validate UAC3 cluster segment descriptors UAC3 class segment descriptors need to be verified whether their sizes match with the declared lengths and whether they fit with the allocated buffer sizes, too. Otherwise malicious firmware may lead to the unexpected OOB accesses.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2025091144-CVE-2025-39757-e212@gregkh/T
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:17760 https://access.redhat.com/errata/RHSA-2025:17760
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:17776 https://access.redhat.com/errata/RHSA-2025:17776