Impact
The Linux kernel for the legacy USB Audio Class 1 gadget defines configfs show/store handlers via the UAC1_STR_ATTRIBUTE macro for three string attributes. The store handler mistakenly checks the result of kstrndup() in reverse order; if the allocation fails it returns –ENOMEM and simultaneously dereferences a NULL pointer. When a write to any of these attributes occurs the kernel crashes, resulting in a system‑wide reboot or halt.
Affected Systems
Any Linux kernel build that includes the legacy UAC1 gadget—i.e., kernels compiled with CONFIG_USB_UAC1_LEGACY and the UAC1_STR_ATTRIBUTE macro—remains vulnerable until the recent commit removes those attributes. No specific kernel version is documented, so all kernels before the patch that still expose the configfs entries are at risk. Custom kernels or modules that enable the legacy gadget and leave the configfs entries exposed are also affected.
Risk and Exploitability
EPSS is below 1 % and the vulnerability is not listed in CISA KEV, indicating a low likelihood of active exploitation. The CVE description does not state the attack vector explicitly, but it is inferred that an attacker must be able to write to the legacy gadget’s configfs entries, a capability normally restricted to users with root or elevated privileges. Thus the primary exploitation scenario is local privileged access leading to denial of service via kernel panic; remote exploitation is unlikely. The CVSS score of 5.5 reflects a medium severity.
OpenCVE Enrichment
Debian DLA
Debian DSA