CVE-2025-40095: Linux
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_rndis: Refactor bind path to use __free() After an bind/unbind cycle, the rndis->notify_req is left stale. If a subsequent bind fails, the unified error label attempts to free this stale request, leading to a NULL pointer dereference when accessing ep->ops->free_request. Refactor the error handling in the bind path to use the __free() automatic cleanup mechanism.
Affected products
- Linux Linux: from 2.6.27, before 6.1.158 (fixed in 6.1.158); from 6.2, before 6.6.114 (fixed in 6.6.114); from 6.7, before 6.12.55 (fixed in 6.12.55); from 6.13, before 6.17.5 (fixed in 6.17.5)
Published 2025-10-30. Last modified 2026-07-30.