Junglewise Threat Intelligence

CVE-2025-40094: Linux Kernel NULL pointer dereference in USB gadget f_acm bind path

CVE-2025-40094 · Severity: high · CVSS 7.8 · Published 2025-10-30

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's USB gadget driver (specifically the Abstract Control Model or ACM function). When a USB device is repeatedly connected and disconnected, the system may fail to properly clean up internal memory requests. If a subsequent connection attempt fails, the system may crash due to a 'null pointer dereference,' potentially leading to a complete system failure or denial of service.

Technical details

A vulnerability in the Linux kernel USB gadget f_acm driver (drivers/usb/gadget/function/f_acm.c) results from a stale pointer in the acm->notify_req structure after a bind/unbind cycle. If a subsequent bind attempt fails, the error handling path attempts to free this stale request via gs_free_req, which triggers a NULL pointer dereference when accessing ep->ops->free_request. The fix refactors the bind path to use the __free() automatic cleanup mechanism to ensure safe memory management. This is a local attack vector requiring the ability to trigger gadget bind/unbind operations, typically resulting in a Denial of Service (kernel panic).

Affected products

  • Linux Linux 2.6.27 to 5.15.196, 6.1.158, 6.6.114, 6.12.55, 6.17.5

Timeline

  • 2025-10-17: patched: Initial fix commit by Kuen-Han Tsai
  • 2025-10-30: disclosed: CVE-2025-40094 published

References