usb_udc_uevent of the component Gadget Driver. The manipulation leads to use after free.This vulnerability was named CVE-2022-49980. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.