Impact
f_midi_alloc initializes a reference counter that can only be incremented when a sound card is registered via f_midi_register_card(). Because INIT_WORK was incorrectly placed in f_midi_bind(), the work structure for the MIDI gadget might remain uninitialized if bind never runs. When the kernel later calls __flush_work, the work structure’s function pointer is null, causing a warning and potentially a kernel panic. The flaw is an unsafe use of an uninitialized object (CWE‑824).
Affected Systems
All Linux kernel releases that expose the f_midi gadget driver before the fix are affected. The vulnerability is present in kernel sources that include the original f_midi_alloc and f_midi_bind implementations, before the change that moves INIT_WORK into f_midi_alloc. No specific kernel series is listed, so any customer running an unpatched Linux kernel that supports the f_midi gadget should consider themselves at risk.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity, but the EPSS score of less than 1 % shows a very low exploitation probability at the time of assessment. The vulnerability is not listed in CISA’s KEV catalog, reinforcing that it is not currently known to be widely exploited. Attackers would need local access to manipulate USB traffic to an uninitialized MIDI gadget; therefore the vector is local and requires some level of kernel interaction. Given the limited exploitation likelihood, it is recommended to patch rather than monitor.
OpenCVE Enrichment
Debian DLA
Debian DSA