Impact
The Linux kernel contains a race in gadget_dev_ioctl where the dev->gadget pointer is read before acquiring dev->lock, while the dev->state check occurs afterwards. A concurrent bind can change the device state between these operations, leaving ioctl with a stale NULL gadget pointer that is dereferenced through gadget->ops->ioctl. This results in a kernel crash, producing a denial‑of‑service for the host system. The weakness manifests as a null pointer dereference and a concurrency problem.
Affected Systems
The flaw affects the generic Linux kernel, with no specific version range listed in the advisory. Any system using a kernel build that includes gadget_dev_ioctl before the patch commit is potentially vulnerable.
Risk and Exploitability
The EPSS score is reported as less than 1 %, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector requires local execution by a process that can invoke the USB gadget ioctl interface; it does not require network access. The impact is a local denial of service through a kernel crash, with the risk tempered by the low exploit probability.
OpenCVE Enrichment
Debian DLA
Debian DSA