Impact
The bug is a use‑after‑free triggered by a race between a call that frees a dwc3 gadget endpoint and a delayed work item that still accesses that endpoint. If the delayed work runs after the endpoint is released, the kernel dereferences a stale pointer, corrupting memory and potentially allowing an attacker to execute arbitrary code in kernel mode or crash the system. This vulnerability falls under CWE‑825.
Affected Systems
All Linux kernel builds that include the dwc3 USB gadget driver – whether compiled into the kernel or loaded as a module – are affected. Because the vendor product listing is generic, the vulnerability applies to every kernel release that ships this driver until the patch that cancels the delayed work is applied.
Risk and Exploitability
The exploitation probability (EPSS) is reported as less than 1 % and the vulnerability is not listed in CISA’s KEV catalog, indicating no known public exploits yet. The CVSS score of 7.0 classifies the issue as high severity, underscoring the seriousness of the potential kernel memory corruption. The likely attack vector would involve a malicious USB device or a user exposing a device to the system while a stream event is queued. An attacker would need to trigger gadget removal concurrently with the stream event to create the race condition. Although the risk of exploitation is low, the potential impact is high – any successful attack would elevate privileges to kernel level or cause a denial of service.
OpenCVE Enrichment