Use-After-Free Vulnerability in Linux Kernel's atcspi200 Driver
CVE-2026-74415
Currently unrated
What is CVE-2026-74415?
A vulnerability exists in the Linux kernel's atcspi200 driver where improper memory management can lead to a use-after-free condition during the unbinding of the driver. Specifically, if the DMA resource is cleaned up while the SPI controller remains active, it may result in unexpected behavior or crashes due to lingering references. This issue underscores the importance of ensuring proper deallocation procedures during driver lifecycle management, particularly in complex I/O operations.
Affected Version(s)
Linux 34e3815ea4597131d4324a4aa243d2201e672005
Linux 34e3815ea4597131d4324a4aa243d2201e672005 < 565bdf45125a05aa8f622f58f598283f46ba43f4
Linux 7.0