CVE-2025-40223
In the Linux kernel, the following vulnerability has been resolved:
most: usb: Fix use-after-free in hdm_disconnect
hdm_disconnect() calls most_deregister_interface(), which eventually unregisters the MOST interface device with device_unregister(iface->dev). If that drops the last reference, the device core may call release_mdev() immediately while hdm_disconnect() is still executing.
The old code also freed several mdev-owned allocations in hdm_disconnect() and then performed additional put_device() calls. Depending on refcount order, this could lead to use-after-free or double-free when release_mdev() ran (or when unregister paths also performed puts).
Leer descripción completaMostrar menos
Fix by moving the frees of mdev-owned allocations into release_mdev(), so they happen exactly once when the device is truly released, and by dropping the extra put_device() calls in hdm_disconnect() that are redundant after device_unregister() and most_deregister_interface().
This addresses the KASAN slab-use-after-free reported by syzbot in hdm_disconnect(). See report and stack traces in the bug link below.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/33daf469f5294b9d07c4fc98216cace9f4f34cc6
- https://git.kernel.org/stable/c/3a3b8e89c7201c5b3b76ac4a4069d1adde1477d6
- https://git.kernel.org/stable/c/4b1270902609ef0d935ed2faa2ea6d122bd148f5
- https://git.kernel.org/stable/c/578eb18cd111addec94c43f61cd4b4429e454809
- https://git.kernel.org/stable/c/5b5c478f09b1b35e7fe6fc9a1786c9bf6030e831
- https://git.kernel.org/stable/c/72427dc6f87523995f4e6ae35a948bb2992cabce
- https://git.kernel.org/stable/c/f93a84ffb884d761a9d4e869ba29c238711e81f1
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-40223",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "97a6f772f36b7f52bcfa56a581bbd2470cffe23d",
"lessThan": "5b5c478f09b1b35e7fe6fc9a1786c9bf6030e831",
"versionType": "git"
},
{
"status": "affected",
"version": "97a6f772f36b7f52bcfa56a581bbd2470cffe23d",
"lessThan": "578eb18cd111addec94c43f61cd4b4429e454809",
"versionType": "git"
},
{
"status": "affected",
"version": "97a6f772f36b7f52bcfa56a581bbd2470cffe23d",
"lessThan": "33daf469f5294b9d07c4fc98216cace9f4f34cc6",
"versionType": "git"
},
{
"status": "affected",
"version": "97a6f772f36b7f52bcfa56a581bbd2470cffe23d",
"lessThan": "72427dc6f87523995f4e6ae35a948bb2992cabce",
"versionType": "git"
},
{
"status": "affected",
"version": "97a6f772f36b7f52bcfa56a581bbd2470cffe23d",
"lessThan": "f93a84ffb884d761a9d4e869ba29c238711e81f1",
"versionType": "git"
},
{
"status": "affected",
"version": "97a6f772f36b7f52bcfa56a581bbd2470cffe23d",
"lessThan": "3a3b8e89c7201c5b3b76ac4a4069d1adde1477d6",
"versionType": "git"
},
{
"status": "affected",
"version": "97a6f772f36b7f52bcfa56a581bbd2470cffe23d",
"lessThan": "4b1270902609ef0d935ed2faa2ea6d122bd148f5",
"versionType": "git"
}
],
"programFiles": [
"drivers/most/most_usb.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.9"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.9",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.246",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.196",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.158",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.115",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.56",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.17.6",
"versionType": "semver",
"lessThanOrEqual": "6.17.*"
},
{
"status": "unaffected",
"version": "6.18",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/most/most_usb.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2025-12-04T16:16:14.767",
"references": [
{
"url": "https://git.kernel.org/stable/c/33daf469f5294b9d07c4fc98216cace9f4f34cc6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/3a3b8e89c7201c5b3b76ac4a4069d1adde1477d6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/4b1270902609ef0d935ed2faa2ea6d122bd148f5",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/578eb18cd111addec94c43f61cd4b4429e454809",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5b5c478f09b1b35e7fe6fc9a1786c9bf6030e831",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/72427dc6f87523995f4e6ae35a948bb2992cabce",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f93a84ffb884d761a9d4e869ba29c238711e81f1",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Deferred",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmost: usb: Fix use-after-free in hdm_disconnect\n\nhdm_disconnect() calls most_deregister_interface(), which eventually\nunregisters the MOST interface device with device_unregister(iface->dev).\nIf that drops the last reference, the device core may call release_mdev()\nimmediately while hdm_disconnect() is still executing.\n\nThe old code also freed several mdev-owned allocations in\nhdm_disconnect() and then performed additional put_device() calls.\nDepending on refcount order, this could lead to use-after-free or\ndouble-free when release_mdev() ran (or when unregister paths also\nperformed puts).\n\nFix by moving the frees of mdev-owned allocations into release_mdev(),\nso they happen exactly once when the device is truly released, and by\ndropping the extra put_device() calls in hdm_disconnect() that are\nredundant after device_unregister() and most_deregister_interface().\n\nThis addresses the KASAN slab-use-after-free reported by syzbot in\nhdm_disconnect(). See report and stack traces in the bug link below."
}
],
"lastModified": "2026-06-17T09:21:29.107",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}