« Volver al listado

CVE-2025-40314

Estado: AplazadaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

usb: cdns3: gadget: Use-after-free during failed initialization and exit of cdnsp gadget

In the __cdnsp_gadget_init() and cdnsp_gadget_exit() functions, the gadget structure (pdev->gadget) was freed before its endpoints. The endpoints are linked via the ep_list in the gadget structure. Freeing the gadget first leaves dangling pointers in the endpoint list. When the endpoints are subsequently freed, this results in a use-after-free.

Fix: By separating the usb_del_gadget_udc() operation into distinct "del" and "put" steps, cdnsp_gadget_free_endpoints() can be executed prior to the final release of the gadget structure with usb_put_gadget().

Leer descripción completaMostrar menos

A patch similar to bb9c74a5bd14("usb: dwc3: gadget: Free gadget structure only after freeing endpoints").

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-40314",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "8bc1901ca7b07d864fca11461b3875b31f949765",
              "lessThan": "0cf9a50af91fbdac3849f8d950e883a3eaa3ecea",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8bc1901ca7b07d864fca11461b3875b31f949765",
              "lessThan": "37158ce6ba964b62d1e3eebd11f03c6900a52dd1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8bc1901ca7b07d864fca11461b3875b31f949765",
              "lessThan": "ea37884097a0931abb8e11e40eacfb25e9fdb5e9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8bc1901ca7b07d864fca11461b3875b31f949765",
              "lessThan": "9c52f01429c377a2d32cafc977465f37b5384f77",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8bc1901ca7b07d864fca11461b3875b31f949765",
              "lessThan": "fdf573c517627a96f5040f988e9b21267806be5c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8bc1901ca7b07d864fca11461b3875b31f949765",
              "lessThan": "87c5ff5615dc0a37167e8faf3adeeddc6f1344a3",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/usb/cdns3/cdnsp-gadget.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.3"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.3",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.15.197",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.159",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.117",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.58",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.17.8",
              "versionType": "semver",
              "lessThanOrEqual": "6.17.*"
            },
            {
              "status": "unaffected",
              "version": "6.18",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/usb/cdns3/cdnsp-gadget.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-12-08T01:16:03.877",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0cf9a50af91fbdac3849f8d950e883a3eaa3ecea",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/37158ce6ba964b62d1e3eebd11f03c6900a52dd1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/87c5ff5615dc0a37167e8faf3adeeddc6f1344a3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9c52f01429c377a2d32cafc977465f37b5384f77",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ea37884097a0931abb8e11e40eacfb25e9fdb5e9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fdf573c517627a96f5040f988e9b21267806be5c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Deferred",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: cdns3: gadget: Use-after-free during failed initialization and exit of cdnsp gadget\n\nIn the __cdnsp_gadget_init() and cdnsp_gadget_exit() functions, the gadget\nstructure (pdev->gadget) was freed before its endpoints.\nThe endpoints are linked via the ep_list in the gadget structure.\nFreeing the gadget first leaves dangling pointers in the endpoint list.\nWhen the endpoints are subsequently freed, this results in a use-after-free.\n\nFix:\nBy separating the usb_del_gadget_udc() operation into distinct \"del\" and\n\"put\" steps, cdnsp_gadget_free_endpoints() can be executed prior to the\nfinal release of the gadget structure with usb_put_gadget().\n\nA patch similar to bb9c74a5bd14(\"usb: dwc3: gadget: Free gadget structure\n only after freeing endpoints\")."
    }
  ],
  "lastModified": "2026-06-17T09:21:38.627",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}