Executive brief
A vulnerability was identified in the Linux kernel's USB gadget driver (specifically the Abstract Control Model or ACM function). When a USB device is repeatedly connected and disconnected, the system may fail to properly clean up internal memory requests. If a subsequent connection attempt fails, the system may crash due to a 'null pointer dereference,' potentially leading to a complete system failure or denial of service.
Technical details
A vulnerability in the Linux kernel USB gadget f_acm driver (drivers/usb/gadget/function/f_acm.c) results from a stale pointer in the acm->notify_req structure after a bind/unbind cycle. If a subsequent bind attempt fails, the error handling path attempts to free this stale request via gs_free_req, which triggers a NULL pointer dereference when accessing ep->ops->free_request. The fix refactors the bind path to use the __free() automatic cleanup mechanism to ensure safe memory management. This is a local attack vector requiring the ability to trigger gadget bind/unbind operations, typically resulting in a Denial of Service (kernel panic).
Affected products
- Linux Linux 2.6.27 to 5.15.196, 6.1.158, 6.6.114, 6.12.55, 6.17.5
Timeline
- 2025-10-17: patched: Initial fix commit by Kuen-Han Tsai
- 2025-10-30: disclosed: CVE-2025-40094 published
References
- https://git.kernel.org/stable/c/201a66d8e6630762e760e1d78f1d149da1691e7b
- https://git.kernel.org/stable/c/2b1546f7c5fc6c44555a8e7a2b34229d1dcd2175
- https://git.kernel.org/stable/c/47b2116e54b4a854600341487e8b55249e926324
- https://git.kernel.org/stable/c/c4301e4dd6b32faccb744f1c2320e64235b68d3b
- https://git.kernel.org/stable/c/c5d116862dd3ed162d079738a5ebddf9fceea850
- https://git.kernel.org/stable/c/e348d18fb0124b662cfefb3001733b49da428215