Impact
The Linux kernel contains a null pointer dereference in usb_put_function_instance() used by the USB gadget subsystem; when an error path in uvc_alloc_inst() attempts to access fi->fd before it has been allocated, the kernel crashes. This results in a denial of service when the gadget subsystem is loaded.
Affected Systems
All Linux kernel implementations that include the gadget subsystem and do not contain the commit adding a null check for fi->fd are affected; distributions shipping those kernel versions remain vulnerable until upgraded to releases that incorporate the fix.
Risk and Exploitability
Based on the description, the likely attack vector would involve a malicious USB device that triggers the gadget subsystem's error path to create the null pointer dereference; the EPSS score of less than 1% suggests exploitation probability is low. The vulnerability is not listed in the CISA KEV catalog, and no CVSS score is provided in the data.
OpenCVE Enrichment
Debian DLA
Debian DSA