CVE-2025-40314 — Linux vulnerability
49 documents7 sources
Severity
7.8HIGHOSV
OSV3.2
No vectorEPSS
0.0%
top 86.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 8
Latest updateApr 13
Description
In the Linux kernel, the following vulnerability has been resolved:
usb: cdns3: gadget: Use-after-free during failed initialization and exit of cdnsp gadget
In the __cdnsp_gadget_init() and cdnsp_gadget_exit() functions, the gadget
structure (pdev->gadget) was freed before its endpoints.
The endpoints are linked via the ep_list in the gadget structure.
Freeing the gadget first leaves dangling pointers in the endpoint list.
When the endpoints are subsequently freed, this results in a use-after-…
Affected Packages7 packages
▶CVEListV5linux/linux8bc1901ca7b07d864fca11461b3875b31f949765 — 0cf9a50af91fbdac3849f8d950e883a3eaa3ecea+6