CVE-2025-40315: Linux

EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Fix epfile null pointer access after ep enable. A race condition occurs when ffs_func_eps_enable() runs concurrently with ffs_data_reset(). The ffs_data_clear() called in ffs_data_reset() sets ffs->epfiles to NULL before resetting ffs->eps_count to 0, leading to a NULL pointer dereference when accessing epfile->ep in ffs_func_eps_enable() after successful usb_ep_enable(). The ffs->epfiles pointer is set to NULL in both ffs_data_clear() and ffs_data_close() functions, and its modification is protected by the spinlock ffs->eps_lock. And the whole ffs_func_eps_enable() function is also protected by ffs->eps_lock. Thus, add NULL pointer handling for ffs->epfiles in the ffs_func_eps_enable() function to fix issues

Affected products

  • Linux Linux: from 5.4.180, before 5.4.302 (fixed in 5.4.302); from 5.10.101, before 5.10.247 (fixed in 5.10.247); from 5.15.24, before 5.15.197 (fixed in 5.15.197); from 4.14.267, before 4.15 (fixed in 4.15); from 4.19.230, before 4.20 (fixed in 4.20); from 5.16.10, before 5.17 (fixed in 5.17); …

Published 2025-12-08. Last modified 2026-06-17.