Impact
In the Linux kernel, the ffs USB gadget driver stores a pointer to the submitting task's mm_struct in the io_data structure but fails to hold a reference to it while asynchronous requests are pending. If the submitting task exits before the request completion handling finishes, the mm_struct can be freed, leading to a use‑after‑free condition. This kernel memory corruption may allow an attacker to influence kernel data structures, potentially resulting in privilege escalation or arbitrary code execution within the kernel context.
Affected Systems
The vulnerability affects all Linux kernel releases that do not include the patch commits referenced in the advisory (e.g. 5eb5c72c72fef, 7411de0ce3b45286de1de82526795658ea6eacb0). Target systems running an unpatched Linux kernel may therefore be exposed.
Risk and Exploitability
The CVSS score is 7.8, indicating high severity, while the EPSS score is below 1%. The vulnerability is not listed in CISA’s KEV catalogue. Exploitation likely requires an attacker’s ability to configure a USB gadget that issues asynchronous FFS read requests while causing the submitting task to terminate prematurely, which typically implies physical access or control over the USB subsystem. Although the low EPSS score suggests infrequent exploitation, the impact of a kernel memory corruption is significant and warrants prompt action.
OpenCVE Enrichment
Debian DLA
Debian DSA