Review reviewHigh

CVE-2025-38555

Linux Linux, linux kernel, debian linux

In the Linux kernel, the following vulnerability has been resolved: usb: gadget : fix use-after-free in composite_dev_cleanup() 1. In func configfs_composite_bind() -> composite_os_desc_req_prepare(): if kmalloc fails, the pointer cdev->os_desc_req will be freed but not set to NULL. Then it will return a failure to the upper-level function. 2. in func configfs_composite_bind() -> composite_dev_cleanup(): it will checks whether cdev->os_desc_req is NULL. If it is not NULL, it will attempt to use it.This will lead to a use-after-free issue. BUG: KASAN: use-after-free in composite_dev_cleanup+...

CVSS
7.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2025.08.20
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: usb: gadget : fix use-after-free in composite_dev_cleanup() 1. In func configfs_composite_bind() -> composite_os_desc_req_prepare(): if kmalloc fails, the pointer cdev->os_desc_req will be freed but not set to NULL. Then it will return a failure to the upper-level function. 2. in func configfs_composite_bind() -> composite_dev_cleanup(): it will checks whether cdev->os_desc_req is NULL. If it is not NULL, it will attempt to use it.This will lead to a use-after-free issue. BUG: KASAN: use-after-free in composite_dev_cleanup+...

Affected product and versions

Product
Linux Linux, linux kernel, debian linux
Affected versions
>= 37a3a533429ef9b3cc9f15a656c19623f0e88df7 < dba96dfa5a0f685b959dd28a52ac8dab0b805204, >= 37a3a533429ef9b3cc9f15a656c19623f0e88df7 < 2db29235e900a084a656dea7e0939b0abb7bb897, >= 37a3a533429ef9b3cc9f15a656c19623f0e88df7 < 8afb22aa063f706f3343707cdfb8cda4d021dd33, >= 37a3a533429ef9b3cc9f15a656c19623f0e88df7 < e624bf26127645a2f7821e73fdf6dc64bad07835, >= 37a3a533429ef9b3cc9f15a656c19623f0e88df7 < aada327a9f8028c573636fa60c0abc80fb8135c9, >= 37a3a533429ef9b3cc9f15a656c19623f0e88df7 < 5f06ee9f9a3665d43133f125c17e5258a13f3963, >= 37a3a533429ef9b3cc9f15a656c19623f0e88df7 < bd3c4ef60baf7f65c963f3e12d9d7b2b091e20ba, >= 37a3a533429ef9b3cc9f15a656c19623f0e88df7 < e1be1f380c82a69f80c68c96a7cfe8759fb30355, >= 37a3a533429ef9b3cc9f15a656c19623f0e88df7 < 151c0aa896c47a4459e07fee7d4843f44c1bb18e, >= 3.16, >= 3.16 < 5.4.297, >= 5.5 < 5.10.241, >= 5.11 < 5.15.190, >= 5.16 < 6.1.148, >= 6.2 < 6.6.102, >= 6.7 < 6.12.42, >= 6.13 < 6.15.10, >= 6.16 < 6.16.1, 11.0
Fixed versions
5.4.297, 5.10.241, 5.15.190, 6.1.148, 6.6.102, 6.12.42, 6.15.10, 6.16.1

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel, debian linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416