PT-2025-44384 · Linux+3 · Linux Kernel+3

Published

2025-09-17

·

Updated

2026-05-07

·

CVE-2025-40094

CVSS v2.0

4.3

Medium

VectorAV:A/AC:H/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw related to USB gadget functionality, specifically within the f acm module. A NULL pointer dereference can occur after a bind/unbind cycle, potentially leading to system instability. This happens when a stale request remains in acm->notify req and a subsequent bind fails, causing an attempt to free this stale request. The issue is addressed by refactoring the error handling in the bind path to utilize the free() automatic cleanup mechanism.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Improper Resource Release

Weakness Enumeration

Related Identifiers

BDU:2026-02717
CVE-2025-40094
DLA-4379-1
DSA-6053-1
ECHO-0074-B65D-17CF
MGASA-2025-0309
MGASA-2025-0310
OPENSUSE-SU-2025:15702-1
OPENSUSE-SU-2026:10301-1
USN-8029-1
USN-8029-2
USN-8029-3
USN-8030-1
USN-8033-1
USN-8033-2
USN-8033-3
USN-8033-4
USN-8033-5
USN-8033-6
USN-8033-7
USN-8033-8
USN-8034-1
USN-8034-2
USN-8048-1
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8100-1
USN-8125-1
USN-8126-1
USN-8141-1
USN-8163-1
USN-8163-2
USN-8165-1
USN-8243-1
USN-8261-1

Affected Products

Debian
Linuxmint
Linux Kernel
Ubuntu