In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_hid: fix refcount leak on error path When failing to allocate report_desc, opts->refcnt has already been incremented so it needs to be decremented to avoid leaving the options structure permanently locked.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2025100702-CVE-2022-50514-cca3@gregkh/T