Impact
A NULL pointer dereference in the Linux USB cdns3 gadget driver causes a kernel crash when an endpoint is disabled or not yet configured. The bug is triggered by a call to __cdns3_gadget_ep_queue() when the ep->desc pointer is NULL, leading to an unhandled dereference and system shutdown. The impact is a denial of service; the system becomes unavailable until reboot.
Affected Systems
All Linux kernel installations that include the cdns3 USB gadget driver and have not yet incorporated the patch are vulnerable. No specific versions are listed, so any kernel embedding this driver before the fix is at risk.
Risk and Exploitability
The CVSS score is 5.5 and the EPSS score is not available, making the exploitation likelihood unclear. The bug can be triggered by an attacker with control over the USB gadget interface, which may be achievable locally or via compromised device configuration. Because the vulnerability leads to a kernel crash, it is not a remote code execution but a severe local denial of service. The vulnerability is not listed as a known exploited vulnerability in the KEV catalog.
OpenCVE Enrichment
Debian DLA
Debian DSA