Impact
The FunctionFS driver in the Linux kernel can enter an interruptible sleep while reading from the control endpoint when ffs->mutex is still held. If a userspace daemon repeatedly reads ep0 while the gadget is being torn down through configfs, the unbinding operation will attempt to acquire the same mutex. Because both sides hold each other’s lock, the kernel deadlocks: the user‑space process is in an interruptible sleep holding the mutex, and the teardown thread waits for the mutex, halting the device and effectively disabling communication. The weakness is identified as CWE‑833.
Affected Systems
All Linux kernel releases that include the FunctionFS gadget driver and are exposed to USB gadget userspace polling are affected. This includes Linux distributions using the default USB gadget stack. Any kernel not patched to the version that contains the fix will remain vulnerable.
Risk and Exploitability
The CVSS score of 4.1 indicates moderate severity, and the EPSS score is below 1%, suggesting a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local control of a USB gadget device and a userspace process that repeatedly reads the control endpoint during a teardown operation; a successful exploit would cause a deadlock that freezes the device and interrupts service.
OpenCVE Enrichment
Debian DSA