Impact
The vulnerability resides in the Linux kernel’s USB gadget UVC driver. During device initialization, the error logging routine dereferences a pointer that has not yet been assigned. This results in a null pointer dereference that causes a kernel panic, interrupting service. The flaw is classified as CWE‑476 and does not provide privilege escalation or data disclosure.
Affected Systems
Linux kernels that load the g_uvc module for USB gadget UVC support are impacted. Any system where this module is enabled and the initialization path can be triggered, such as, is susceptible until the patch is applied.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate severity, while the EPSS score of less than 1% shows a very low expected exploitation probability. The likely attack vector is an attacker having the ability to supply a USB gadget device that activates the UVC driver’s initialization failure path, implying physical or local USB device injection rather than remote exploitation. Upon exploitation, the kernel panic results in a denial of service but does not leak information or grant elevated privileges. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment