cbcvebase.
CVE-2025-40315
published 2025-12-08

CVE-2025-40315: In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Fix epfile null pointer access after ep enable. A race condition occurs…

PriorityP421high7.8
EPSS
0.20%
9.6th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Fix epfile null pointer access after ep enable. A race condition occurs when ffs_func_eps_enable() runs concurrently with ffs_data_reset(). The ffs_data_clear() called in ffs_data_reset() sets ffs->epfiles to NULL before resetting ffs->eps_count to 0, leading to a NULL pointer dereference when accessing epfile->ep in ffs_func_eps_enable() after successful usb_ep_enable(). The ffs->epfiles pointer is set to NULL in both ffs_data_clear() and ffs_data_close() functions, and its modification is protected by the spinlock ffs->eps_lock. And the whole ffs_func_eps_enable() function is also protected by ffs->eps_lock. Thus, add NULL pointer handling for ffs->epfiles in the ffs_func_eps_enable() function to fix issues

Affected

39 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
debianlinux-6.1< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 0042178a69eb77a979e36a50dcce9794a3140ef8 < 1c0dbd240be3f87cac321b14e17979b7e9cb6a8f1c0dbd240be3f87cac321b14e17979b7e9cb6a8f
linuxlinux>= 4.14.267 < 4.154.15
linuxlinux>= 4.19.230 < 4.204.20
linuxlinux>= 5.10.101 < 5.10.2475.10.247
linuxlinux>= 5.15.24 < 5.15.1975.15.197
linuxlinux>= 5.16.10 < 5.175.17
linuxlinux>= 5.4.180 < 5.4.3025.4.302
linuxlinux>= 72a8aee863af099d4434314c4536d6c9a61dcf3c < 9ec40fba7357df2d36f4c2e2f3b9b1a4fba0a2729ec40fba7357df2d36f4c2e2f3b9b1a4fba0a272
linuxlinux>= c9fc422c9a43e3d58d246334a71f3390401781dc < b00d2572c16e8e59e979960d3383c2ae9cebd195b00d2572c16e8e59e979960d3383c2ae9cebd195
linuxlinux>= ebe2b1add1055b903e2acd86b290a85297edc0b3 < c53e90563bc148e4e0ad09fe130ba2246d426ea6c53e90563bc148e4e0ad09fe130ba2246d426ea6
linuxlinux>= ebe2b1add1055b903e2acd86b290a85297edc0b3 < fc1141a530dfc91f0ee19b7f422a2d24829584bcfc1141a530dfc91f0ee19b7f422a2d24829584bc
linuxlinux>= ebe2b1add1055b903e2acd86b290a85297edc0b3 < d62b808d5c68a931ad0849a00a5e3be3dd7e0019d62b808d5c68a931ad0849a00a5e3be3dd7e0019
linuxlinux>= ebe2b1add1055b903e2acd86b290a85297edc0b3 < 30880e9df27332403dd638a82c27921134b3630b30880e9df27332403dd638a82c27921134b3630b
linuxlinux>= ebe2b1add1055b903e2acd86b290a85297edc0b3 < cfd6f1a7b42f62523c96d9703ef32b0dbc495ba4cfd6f1a7b42f62523c96d9703ef32b0dbc495ba4
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.159-16.1.159-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.8-16.17.8-1
linuxlinux_kernel>= 0 < 5.4.3025.4.302

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.