CVE-2025-40269: ALSA: usb-audio: Fix potential overflow of PCM transfer buffer
Published Dec 6, 2025
·Updated
ALSA: usb-audio: Fix potential overflow of PCM transfer buffer
Affected Software
7 affected componentsFixes available
linux/linux
Microsoft azl3 kernel 6.6.112.1-2
Microsoft azl3 kernel 6.6.112.1-2
IBM Verify Identity Access<=11.0 - 11.0.2
IBM Security Verify Access<=10.0 - 10.0.9.1
IBM Verify Identity Access Container<=11.0 - 11.0.2
IBM Security Verify Access Container<=10.0 - 10.0.9.1
Event History
Dec 6, 2025
CVE Published
via MITRE·09:50 PM
Data Sourced
via MITRE·09:50 PM
Description
Data Sourced
via NVD·10:15 PM
Description
Dec 8, 2025
Data Sourced
via Microsoft·01:01 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·01:01 AM
DescriptionSeverity
Data Sourced
via Red Hat·07:08 AM
DescriptionSeverityAffected Software
Jul 8, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-40269?
CVE-2025-40269 is classified as a moderate severity vulnerability in the Linux kernel.
2
What type of vulnerability is CVE-2025-40269?
CVE-2025-40269 is a buffer overflow vulnerability in the ALSA USB audio driver.
3
How do I fix CVE-2025-40269?
To fix CVE-2025-40269, update your Linux kernel to the latest stable version that includes the patch.
4
What systems are affected by CVE-2025-40269?
CVE-2025-40269 affects systems using the Linux kernel that utilize the ALSA USB audio driver.
5
How can CVE-2025-40269 be exploited?
CVE-2025-40269 can potentially be exploited through crafted USB audio packets that lead to buffer overflow.