Impact
The Linux kernel usb gadget midi2 driver allocates default configfs child groups for the endpoint and block when a midi2 instance is created, setting their reference counts to one. During device teardown or endpoint cleanup, the function configfs_remove_default_groups() is never called, leaving the reference counts unreleased and leaking the structures f_midi2_ep_opts and f_midi2_block_opts. This results repeated creation and removal of midi instances, potentially exhausting kernel memory and causing kernel instability or a denial of service. The weakness is a form of improper resource management (CWE‑911).
Affected Systems
All Linux kernel releases that include the unpatched usb gadget midi2 driver are affected. No specific kernel version is enumerated; the issue applies universally to kernels containing this driver module.
Risk and Exploitability
The CVSS score of 4.4 and the EPSS score of < 1% suggest a low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is interaction with the USB gadget interface; a local or remote user capable of loading or configuring the midi2 gadget would need sufficient privileges to trigger the leak. Because the flaw is a memory leak rather than direct code execution, the immediate risk is moderate but repetition could ultimately lead to denial of service.
OpenCVE Enrichment
Debian DSA