CVE-2025-40314 describes a use-after-free vulnerability in the Linux kernel's Cadence USB3 Device Controller (CDNS3) gadget driver. This flaw occurs during the initialization or exit of the cdnsp gadget, where the gadget structure is freed before its associated endpoints, leading to dangling pointers and a subsequent use-after-free when the endpoints are later processed. While specific affected products are not listed, it impacts systems utilizing this particular USB driver. The vulnerability has no assigned CVSS score, but its FAUCET Risk Score is 7/100, indicating a low to moderate severity. The attack vector would likely involve local access or a specially crafted USB device interaction, with the potential impact being system instability, crashes, or possibly arbitrary code execution, though the complexity of exploitation is not detailed. There is no evidence of active exploitation, exploit code availability (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE. It is not listed in the CISA KEV catalog, suggesting it is not currently a high-priority threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 5.3CNA affecteddefault affected | |
| Linux | Linux | >= 8bc1901ca7b07d864fca11461b3875b31f949765, < 0cf9a50af91fbdac3849f8d950e883a3eaa3ecea, >= 8bc1901ca7b07d864fca11461b3875b31f949765, < 37158ce6ba964b62d1e3eebd11f03c6900a52dd1, >= 8bc1901ca7b07d864fca11461b3875b31f949765, < 87c5ff5615dc0a37167e8faf3adeeddc6f1344a3, >= 8bc1901ca7b07d864fca11461b3875b31f949765, < 9c52f01429c377a2d32cafc977465f37b5384f77, >= 8bc1901ca7b07d864fca11461b3875b31f949765, < ea37884097a0931abb8e11e40eacfb25e9fdb5e9, >= 8bc1901ca7b07d864fca11461b3875b31f949765, < fdf573c517627a96f5040f988e9b21267806be5cCNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
Linux kernel (Xilinx) vulnerabilities
May 7, 2026Linux kernel (Azure) vulnerabilities
May 7, 2026Linux kernel (Azure) vulnerabilities
Apr 13, 2026Linux kernel (Azure FIPS) vulnerabilities
Apr 9, 2026Linux kernel (Azure FIPS) vulnerabilities
Apr 9, 2026Linux kernel (Raspberry Pi) vulnerabilities
Apr 1, 2026Linux kernel (Raspberry Pi) vulnerabilities
Apr 1, 2026Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (AWS) vulnerabilities
Mar 23, 2026Linux kernel (NVIDIA Tegra IGX) vulnerabilities
Mar 23, 2026Linux kernel (Intel IoTG Real-time) vulnerabilities
Mar 23, 2026Linux kernel (Real-time) vulnerabilities
Mar 17, 2026Linux kernel vulnerabilities
Mar 17, 2026Linux kernel (Real-time) vulnerabilities
Mar 17, 2026Linux kernel (FIPS) vulnerabilities
Mar 16, 2026Linux kernel (FIPS) vulnerabilities
Mar 16, 2026Linux kernel (NVIDIA) vulnerabilities
Mar 16, 2026Linux kernel vulnerabilities
Mar 16, 2026Linux kernel vulnerabilities
Mar 16, 2026Linux kernel (Azure) vulnerabilities
Feb 24, 2026usb: cdns3: gadget: Use-after-free during failed initialization and exit of cdnsp gadget
Dec 9, 2025kernel: usb: cdns3: gadget: Use-after-free during failed initialization and exit of cdnsp gadget
Dec 8, 2025