Wind River Support Network

HomeDefectsLIN1023-16662
Acknowledged

LIN1023-16662 : Security Advisory - linux - CVE-2025-40093

Created: Oct 31, 2025    Updated: Nov 4, 2025
Found In Version: 10.23.30.1
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:[EOL][EOL]usb: gadget: f_ecm: Refactor bind path to use __free()[EOL][EOL]After an bind/unbind cycle, the ecm->notify_req is left stale. If a[EOL]subsequent bind fails, the unified error label attempts to free this[EOL]stale request, leading to a NULL pointer dereference when accessing[EOL]ep->ops->free_request.[EOL][EOL]Refactor the error handling in the bind path to use the __free()[EOL]automatic cleanup mechanism.
Live chat
Online