SB2025082030 - Use-after-free in Linux kernel usb gadget driver
Published: August 20, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Use-after-free (CVE-ID: CVE-2025-38555)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the composite_os_desc_req_prepare() function in drivers/usb/gadget/composite.c. A local user can escalate privileges on the system.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/151c0aa896c47a4459e07fee7d4843f44c1bb18e
- https://git.kernel.org/stable/c/5f06ee9f9a3665d43133f125c17e5258a13f3963
- https://git.kernel.org/stable/c/aada327a9f8028c573636fa60c0abc80fb8135c9
- https://git.kernel.org/stable/c/bd3c4ef60baf7f65c963f3e12d9d7b2b091e20ba
- https://git.kernel.org/stable/c/e1be1f380c82a69f80c68c96a7cfe8759fb30355
- https://git.kernel.org/stable/c/e624bf26127645a2f7821e73fdf6dc64bad07835