PT-2026-4474 · Linux · Linux Kernel

Published

2025-01-01

·

Updated

2026-04-20

·

CVE-2025-71158

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel's gpio/mpsse driver. Specifically, when an interrupt request (IRQ) worker is active, disconnecting the device can lead to a system crash. This issue stemmed from the driver being initially designed for hardware not intended for hotplugging, leading to the lack of proper handling for device disconnections during worker execution. The resolution involves utilizing a spinlock to safeguard a list of workers and ensure they are properly terminated upon disconnection.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

CVE-2025-71158
ECHO-5E8F-C51D-10E6

Affected Products

Linux Kernel