Impact
A null-pointer dereference occurs in the Linux kernel’s USB MIDI 2.0 gadget when cleaning up an endpoint that was never initialized. During gadget bind, an OUT endpoint is intentionally skipped, leaving usb_ep->card unset. Later, when the host sets an alternate setting, the kernel unconditionally stops both IN and OUT endpoints, calling f_midi2_free_ep_reqs(). For the uninitialized endpoint the function dereferences usb_ep->card, causing a kernel crash. This results in a denial‑of‑service condition on the device. The fix changes the function to use usb_ep->num_reqs, which is safely set to zero for uninitialized endpoints.
Affected Systems
The vulnerability affects the Linux Kernel, specifically builds that include the USB gadget midi2 driver. No version numbers are provided in the advisory, so all kernels that expose this functionality before the patch are potentially affected. Commonly impacted systems are embedded Linux devices or single‑board computers configured to present a USB MIDI 2.0 gadget via configfs.
Risk and Exploitability
The CVSS score is not reported, but the EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation in the wild. The likely attack vector is local or device‑host based: an attacker would need to connect a malicious host that drives the gadget to set an alternate setting after the gadget has been bound. If successful, the target device would crash, causing a denial of service. While the risk remains low due to limited exploitation likelihood, the impact is severe for systems that rely on continuous operation as a USB accessory.
OpenCVE Enrichment
Debian DLA
Debian DSA