Impact
The Linux kernel exposes a use‑after‑free condition in the f_midi2 USB gadget when the string attribute show path is accessed concurrently with a write. The flaw arises because the show routine dereferences a pointer that may have been freed by a parallel store operation, allowing an attacker to read a dangling pointer and potentially trigger kernel memory corruption. The vulnerability is a classic Use‑After‑Free (CWE‑416) and could lead to a crash or, if exploited further, local privilege escalation or code execution.
Affected Systems
Linux kernels that include the USB gadget f_midi2 driver prior to the patch. The affected code paths involve the opts_str_show functions used for exposing device attributes. No specific kernel versions are listed, so any kernel build containing the f_midi2 driver without the fix is potentially vulnerable. The vulnerability is present in both the generic Linux kernel and any derivative distributions that ship the driver unpatched.
Risk and Exploitability
The final CVSS score of 7.8 indicates a high severity with potential for local code execution. The EPSS score is less than 1 %, suggesting low exploitation probability as of now, and the advisory is not present in CISA’s KEV catalog. The attack vector is likely local, requiring access to the f_midi2 sysfs attributes, but an attacker could trigger the race condition by performing a concurrent read and write. Successful exploitation could crash the kernel or provide a foothold for further privilege escalation.
OpenCVE Enrichment
Debian DLA
Debian DSA