CVE-2025-40093
Published Oct 30, 2025
Modified Apr 15, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ecm: Refactor bind path to use __free() After an bind/unbind cycle, the ecm->notify_req is left stale. If a subsequent bind fails, the unified error label attempts to free this stale request, leading to a NULL pointer dereference when accessing ep->ops->free_request. Refactor the error handling in the bind path to use the __free() automatic cleanup mechanism.
Is your site exposed to CVE-2025-40093?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/070f341d86cf2c098d63e484a86c7c1d2696a868
https://git.kernel.org/stable/c/15b9faf53ba8719700596e7ef78879ce200e8c2e
https://git.kernel.org/stable/c/42988380ac67c76bb9dff8f77d7ef3eefd50b7b5
https://git.kernel.org/stable/c/4630c68bade82f087eaaab22e9a361da2f18d139
https://git.kernel.org/stable/c/d3745aaef19198d0c81637a7dd50ef53c4f879b7
Frequently Asked Questions
What is CVE-2025-40093? +
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: f_ecm: Refactor bind path to use __free()
After an bind/unbind cycle, the ecm->notify_req is left stale. If a
subsequent bind fails, the unified error label attempts to free this
stale request, leading to a NULL pointer dereference when accessing
ep->ops->free_request.
Refactor the error handling in the bind path to use the __free()
automatic cleanup mechanism.
How do I check if I'm vulnerable to CVE-2025-40093? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.