FlawAtlas
Search the atlas
CVE-2025-38555 Not scored

usb: gadget : fix use-after-free in composite_dev_cleanup()

In the Linux kernel, the following vulnerability has been resolved: usb: gadget : fix use-after-free in composite_dev_cleanup() 1. In func configfs_composite_bind() -> composite_os_desc_req_prepare(): if kmalloc fails, the pointer cdev->os_desc_req will be freed but not set to NULL. Then it will return a failure to the upper-level function. 2. in func configfs_composite_bind() -> composite_dev_cleanup(): it will checks whether cdev->os_desc_req is NULL. If it is not NULL, it will attempt to use it.This will lead to a use-after-free issue. BUG: KASAN: use-after-free in composite_dev_cleanup+0xf4/0x2c0 Read of size 8 at addr 0000004827837a00 by task init/1 CPU: 10 PID: 1 Comm: init Tainted: G O 5.10.97-oh #1 kasan_report+0x188/0x1cc __asan_load8+0xb4/0xbc composite_dev_cleanup+0xf4/0x2c0 configfs_composite_bind+0x210/0x7ac udc_bind_to_driver+0xb4/0x1ec usb_gadget_probe_driver+0xec/0x21c gadget_dev_desc_UDC_store+0x264/0x27c

Exploit probability 0.2%
Published August 19, 2025
Required by Not available
Last source change July 15, 2026

02 / AFFECTED SOFTWARE

Affected packages

Linux Kernel
Unknown Unknown

03 / CONNECTIONS

Connected vulnerabilities

related OPENSUSE-SU-2025:20081-1
related SUSE-SU-2025:03272-1
related SUSE-SU-2025:03283-1
related SUSE-SU-2025:03290-1
related SUSE-SU-2025:03301-1
related SUSE-SU-2025:03314-1
related SUSE-SU-2025:03315-1
related SUSE-SU-2025:03317-1
related SUSE-SU-2025:03318-1
related SUSE-SU-2025:03319-1
related SUSE-SU-2025:03321-1
related SUSE-SU-2025:03341-1
related SUSE-SU-2025:03343-1
related SUSE-SU-2025:03344-1
related SUSE-SU-2025:03370-1
related SUSE-SU-2025:03374-1
related SUSE-SU-2025:03375-1
related SUSE-SU-2025:03381-1
related SUSE-SU-2025:03382-1
related SUSE-SU-2025:03383-1
related SUSE-SU-2025:03387-1
related SUSE-SU-2025:03389-1
related SUSE-SU-2025:03391-1
related SUSE-SU-2025:03392-1
related SUSE-SU-2025:03393-1
related SUSE-SU-2025:03395-1
related SUSE-SU-2025:03396-1
related SUSE-SU-2025:03397-1
related SUSE-SU-2025:03400-1
related SUSE-SU-2025:03403-1
related SUSE-SU-2025:03406-1
related SUSE-SU-2025:03408-1
related SUSE-SU-2025:03410-1
related SUSE-SU-2025:03411-1
related SUSE-SU-2025:03412-1
related SUSE-SU-2025:03413-1
related SUSE-SU-2025:03418-1
related SUSE-SU-2025:03419-1
related SUSE-SU-2025:03602-1
related SUSE-SU-2025:03633-1
related SUSE-SU-2025:03634-1
related SUSE-SU-2025:20653-1
related SUSE-SU-2025:20669-1
related SUSE-SU-2025:20722-1
related SUSE-SU-2025:20723-1
related SUSE-SU-2025:20724-1
related SUSE-SU-2025:20725-1
related SUSE-SU-2025:20726-1
related SUSE-SU-2025:20727-1
related SUSE-SU-2025:20728-1
related SUSE-SU-2025:20729-1
related SUSE-SU-2025:20730-1
related SUSE-SU-2025:20731-1
related SUSE-SU-2025:20732-1
related SUSE-SU-2025:20733-1
related SUSE-SU-2025:20734-1
related SUSE-SU-2025:20735-1
related SUSE-SU-2025:20736-1
related SUSE-SU-2025:20737-1
related SUSE-SU-2025:20738-1
related SUSE-SU-2025:20739-1
related SUSE-SU-2025:20756-1
related SUSE-SU-2025:20768-1
related SUSE-SU-2025:20769-1
related SUSE-SU-2025:20770-1
related SUSE-SU-2025:20771-1
related SUSE-SU-2025:20772-1
related SUSE-SU-2025:20773-1
related SUSE-SU-2025:20774-1
related SUSE-SU-2025:20784-1
related SUSE-SU-2025:20785-1
related SUSE-SU-2025:20786-1
related SUSE-SU-2025:20787-1
related SUSE-SU-2025:20788-1
related SUSE-SU-2025:20789-1
related SUSE-SU-2025:20790-1
related SUSE-SU-2025:20791-1
related SUSE-SU-2025:21074-1
related SUSE-SU-2025:21139-1
related SUSE-SU-2025:21179-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2025-38555

In the Linux kernel, the following vulnerability has been resolved: usb: gadget : fix use-after-free in composite_dev_cleanup() 1. In func configfs_composite_bind() -> composite_os_desc_req_prepare(): if kmalloc fails, the pointer cdev->os_desc_req will be freed but not set to NULL. Then it will return a failure to the upper-level function. 2. in func configfs_composite_bind() -> composite_dev_cleanup(): it will checks whether cdev->os_desc_req is NULL. If it is not NULL, it will attempt to use it.This will lead to a use-after-free issue. BUG: KASAN: use-after-free in composite_dev_cleanup+0xf4/0x2c0 Read of size 8 at addr 0000004827837a00 by task init/1 CPU: 10 PID: 1 Comm: init Tainted: G O 5.10.97-oh #1 kasan_report+0x188/0x1cc __asan_load8+0xb4/0xbc composite_dev_cleanup+0xf4/0x2c0 configfs_composite_bind+0x210/0x7ac udc_bind_to_driver+0xb4/0x1ec usb_gadget_probe_driver+0xec/0x21c gadget_dev_desc_UDC_store+0x264/0x27c

View original source

05 / REFERENCES

Further evidence