Junglewise Threat Intelligence

CVE-2025-71158: Linux Kernel crash in MPSSE GPIO driver during device disconnect

CVE-2025-71158 · Severity: high · CVSS 7.8 · Published 2026-01-23

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's MPSSE GPIO driver could cause a system crash when a device is unplugged while an interrupt worker is still running. This affects systems using specific USB-to-GPIO hardware interfaces that were not originally designed for hot-plugging. An exploit could lead to a complete system failure or denial of service.

Technical details

A race condition and improper teardown mechanism exist in the gpio-mpsse driver within the Linux kernel. When an IRQ worker is active, unplugging the associated USB device triggers a kernel crash because the worker thread is not properly synchronized or terminated during the disconnect sequence. The fix introduces a spinlock to protect the worker list and ensures all polling workers are correctly torn down upon device disconnection. This vulnerability is primarily a local denial-of-service (system crash) but is rated high by the vendor due to potential stability impacts. Patches have been released for stable kernel branches including 6.18.6 and 6.19.

Affected products

  • Linux Linux Kernel 6.13 to 6.18.5

Timeline

  • 2026-01-23: advisory
  • 2026-01-17: patched

References

Related threats