CVE-2025-71158: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: gpio: mpsse: ensure worker is torn down When an IRQ worker is running, unplugging the device would cause a crash. The sealevel hardware this driver was written for was not hotpluggable, so I never realized it. This change uses a spinlock to protect a list of workers, which it tears down on disconnect.

Affected products

  • Linux Linux Kernel: from 6.13, before 6.18.6 (fixed in 6.18.6)

Published 2026-01-23. Last modified 2026-07-30.