A vulnerability, which was classified as critical, has been found in Linux Kernel up to 5.15.195/6.1.157/6.6.113/6.12.54/6.17.4. Impacted is the function __free of the component usb. Performing manipulation results in null pointer dereference.

This vulnerability is known as CVE-2025-40092. Access to the local network is required for this attack. No exploit is available.

It is advisable to upgrade the affected component.