Impact
The flaw exists in the Linux kernel’s USB gadget driver for r8a66597. During probe, if usb_add_gadget_udc() fails, the code frees the ep0_req structure twice: once in the err_add_udc path and again in clean_up2. This double free can corrupt heap memory and may allow an attacker with suitable privileges to execute arbitrary code or crash the system. The weakness is a classic double free bug.
Affected Systems
Any system running a Linux kernel that includes the r8a66597 gadget driver and has the driver compiled or loaded. The vulnerability is present in the source tree where the patch is applied; specific version numbers are not provided in the data, so affected releases must be verified against the Linux kernel commit that introduced the fix.
Risk and Exploitability
The CVSS score is not supplied, but the EPSS indicates the exploitation probability is below 1%, suggesting limited known exploitation activity. The vulnerability is not listed in the CISA KEV catalog, which further implies a lower likelihood of widespread attacks. Inferred from the description, the typical attack vector would require local or kernel‑level privileges to load or interact with the affected USB gadget driver. Nevertheless, a double free can lead to severe consequences, so administrators should treat it as a high‑risk bug.
OpenCVE Enrichment
Debian DLA
Debian DSA