Impact
A null pointer dereference occurs in the Linux kernel USB Mass Storage gadget driver when the buffer count configuration is set to 0 or 1, bypassing the intended minimum of 2. The driver attempts to set up pointers based on this value, and with a null pointer the kernel crashes. The crash results in a loss of system responsiveness and a kernel panic, potentially allowing an attacker to destabilize the device and force a reboot. Because the fault happens in kernel space, an attacker who can influence the gadget configuration may be able to exploit the crash to gain elevated privileges, though that scenario is not explicitly confirmed by the current information.
Affected Systems
All Linux systems that compile the f_mass_storage gadget driver into the kernel and do not apply the referenced patches are affected. The vulnerability is not tied to a specific kernel release in the advisory, which means any distribution or custom build that includes the unpatched driver is potentially vulnerable. Users of mainstream distributions with the default kernel configuration, as well as developers building custom kernels for embedded or IoT devices, should verify whether the driver is included and whether the patch has been applied.
Risk and Exploitability
The EPSS score indicates a probability of exploitation below 1%, and the vulnerability is not listed in CISA’s KEV catalogue, suggesting no widespread exploitation at present. Exploitation would require an attacker with access to the USB interface or the ability to modify gadget configuration data, implying a local or close-proximity attack vector. While the immediate effect is a denial of service via a kernel crash, the underlying null pointer could also be leveraged for privilege escalation if an attacker can trigger the crash repeatedly to influence kernel memory or control flow. The absence of a CVSS score does not negate the high impact of a kernel panic, but the low EPSS suggests the risk to most deployments remains moderate until a patch is applied.
OpenCVE Enrichment