Use-After-Free Vulnerability in Linux Kernel's atcspi200 Driver
CVE-2026-74415

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
15 August 2026

What is CVE-2026-74415?

A vulnerability exists in the Linux kernel's atcspi200 driver where improper memory management can lead to a use-after-free condition during the unbinding of the driver. Specifically, if the DMA resource is cleaned up while the SPI controller remains active, it may result in unexpected behavior or crashes due to lingering references. This issue underscores the importance of ensuring proper deallocation procedures during driver lifecycle management, particularly in complex I/O operations.

Affected Version(s)

Linux 34e3815ea4597131d4324a4aa243d2201e672005

Linux 34e3815ea4597131d4324a4aa243d2201e672005 < 565bdf45125a05aa8f622f58f598283f46ba43f4

Linux 7.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.