Use-After-Free Vulnerability in Linux Kernel Impacting cdnsp Gadget Functionality
CVE-2025-40314

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
8 December 2025

What is CVE-2025-40314?

A use-after-free vulnerability exists in the Linux kernel's cdnsp gadget due to improper management of memory during the initialization and exit processes. This issue arises when the gadget structure is freed prior to its associated endpoints, leading to the potential dereferencing of dangling pointers. As a result, when the freed endpoints are accessed, it can lead to unpredictable behavior and security risks. A mitigation has been introduced by restructuring the memory management operations, ensuring that endpoint structures are properly freed before releasing the gadget structure itself.

Affected Version(s)

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 0cf9a50af91fbdac3849f8d950e883a3eaa3ecea

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 37158ce6ba964b62d1e3eebd11f03c6900a52dd1

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.