cbcvebase.
CVE-2025-40314
published 2025-12-08

CVE-2025-40314: In the Linux kernel, the following vulnerability has been resolved: usb: cdns3: gadget: Use-after-free during failed initialization and exit of cdnsp gadget In…

PriorityP423high7.8
EPSS
0.17%
6.7th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: cdns3: gadget: Use-after-free during failed initialization and exit of cdnsp gadget In the __cdnsp_gadget_init() and cdnsp_gadget_exit() functions, the gadget structure (pdev->gadget) was freed before its endpoints. The endpoints are linked via the ep_list in the gadget structure. Freeing the gadget first leaves dangling pointers in the endpoint list. When the endpoints are subsequently freed, this results in a use-after-free. Fix: By separating the usb_del_gadget_udc() operation into distinct "del" and "put" steps, cdnsp_gadget_free_endpoints() can be executed prior to the final release of the gadget structure with usb_put_gadget(). A patch similar to bb9c74a5bd14("usb: dwc3: gadget: Free gadget structure only after freeing endpoints").

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
debianlinux-6.1< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
linuxlinux
linuxlinux>= 8bc1901ca7b07d864fca11461b3875b31f949765 < 0cf9a50af91fbdac3849f8d950e883a3eaa3ecea0cf9a50af91fbdac3849f8d950e883a3eaa3ecea
linuxlinux>= 8bc1901ca7b07d864fca11461b3875b31f949765 < 37158ce6ba964b62d1e3eebd11f03c6900a52dd137158ce6ba964b62d1e3eebd11f03c6900a52dd1
linuxlinux>= 8bc1901ca7b07d864fca11461b3875b31f949765 < ea37884097a0931abb8e11e40eacfb25e9fdb5e9ea37884097a0931abb8e11e40eacfb25e9fdb5e9
linuxlinux>= 8bc1901ca7b07d864fca11461b3875b31f949765 < 9c52f01429c377a2d32cafc977465f37b5384f779c52f01429c377a2d32cafc977465f37b5384f77
linuxlinux>= 8bc1901ca7b07d864fca11461b3875b31f949765 < fdf573c517627a96f5040f988e9b21267806be5cfdf573c517627a96f5040f988e9b21267806be5c
linuxlinux>= 8bc1901ca7b07d864fca11461b3875b31f949765 < 87c5ff5615dc0a37167e8faf3adeeddc6f1344a387c5ff5615dc0a37167e8faf3adeeddc6f1344a3
linuxlinux_kernel>= 0 < 6.1.159-16.1.159-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.8-16.17.8-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 5.16.0 < 6.1.1596.1.159
linuxlinux_kernel>= 5.3.0 < 5.15.1975.15.197
linuxlinux_kernel>= 6.13.0 < 6.17.86.17.8
linuxlinux_kernel>= 6.2.0 < 6.6.1176.6.117
linuxlinux_kernel>= 6.7.0 < 6.12.586.12.58
msrcazl3_kernel_6.6.112.1-2_on_azure_linux_3.0
ubuntulinux-aws
ubuntulinux-azure-5.15
ubuntulinux-oracle
ubuntulinux-xilinx

CVSS provenance

osv7.8HIGH
vendor_msrc7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.