In the Linux kernel, the following vulnerability has been resolved:
usb: gadget : fix use-after-free in compositedevcleanup()
BUG: KASAN: use-after-free in compositedevcleanup+0xf4/0x2c0 Read of size 8 at addr 0000004827837a00 by task init/1
CPU: 10 PID: 1 Comm: init Tainted: G O 5.10.97-oh #1 kasan_report+0x188/0x1cc _asanload8+0xb4/0xbc compositedevcleanup+0xf4/0x2c0 configfscompositebind+0x210/0x7ac udcbindtodriver+0xb4/0x1ec usbgadgetprobedriver+0xec/0x21c gadgetdevdescUDCstore+0x264/0x27c
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38555.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-38555.json"
[
{
"signature_version": "v1",
"target": {
"file": "drivers/usb/gadget/composite.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5f06ee9f9a3665d43133f125c17e5258a13f3963",
"deprecated": false,
"digest": {
"line_hashes": [
"110031121572472490324864512579445349585",
"311198416667344627492674293804538284780",
"45420745040127002462426295928943408628",
"244696824880363959874001201144454453251"
],
"threshold": 0.9
},
"id": "CVE-2025-38555-486797ce",
"signature_type": "Line"
},
{
"signature_version": "v1",
"target": {
"file": "drivers/usb/gadget/composite.c",
"function": "composite_os_desc_req_prepare"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5f06ee9f9a3665d43133f125c17e5258a13f3963",
"deprecated": false,
"digest": {
"function_hash": "159537467924938735947546940550678341904",
"length": 509.0
},
"id": "CVE-2025-38555-f7a2b09a",
"signature_type": "Function"
}
]