Impact
This vulnerability occurs when the kernel's USB gadget configfs subsystem reads beyond the end of the qw_sign field due to a mismatch between the byte count and the code‑unit count used in the conversion routines. The bug allows an attacker who can read the configfs attribute to retrieve bytes that belong to adjacent members of the gadget_info structure, potentially exposing kernel data that should be private. The underlying weakness is an out‑of‑bounds read, classified as CWE‑119, and can result in information exposure (CWE‑200).
Affected Systems
The issue is present in the Linux kernel wherever the usb: gadget: configfs subsystem is enabled. The exact kernel versions before the changes introduced in the referenced commits are not enumerated, but any kernel derived from the revision preceding commit 36315a330e067f7773196940552feacb1debbef1 is affected.
Risk and Exploitability
The CVSS score is not reported, but the EPSS score is below 1 %, indicating a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the attacker to have access to the configfs USB gadget attribute, which is normally restricted to privileged users or root. Therefore, while the data exposure could be significant if exploited, the overall risk for most deployments remains modest.
OpenCVE Enrichment
Debian DLA
Debian DSA