Impact
The Linux kernel USB gadget f_fs driver contains a flaw in ffs_dmabuf_transfer() error paths. When an endpoint is disabled or a request allocation fails, the code jumps to err_fence_put which calls dma_fence_put on a DMA fence that has only been allocated with kmalloc and not initialized. This misuse of the fence triggers undefined behavior that could destabilize the kernel.
Affected Systems
All Linux kernel builds that include the USB gadget f_fs driver are affected. The vulnerability exists in any kernel configuration where the f_fs module is compiled in, regardless of distribution or version, until the corresponding kernel patch is applied.
Risk and Exploitability
CVSS score of 7 classifies the issue as moderate severity. EPSS score of <1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is inferred to involve triggering the error path by causing an endpoint shutdown or memory allocation failure while the f_fs driver is active, which could be achieved through interaction with a malicious USB gadget device or host. However, this inference is not directly stated in the advisory. Exploitation would require the driver to be loaded and would lead to undefined behavior that could destabilize the kernel.
OpenCVE Enrichment
Debian DLA
Debian DSA