Impact
The Linux kernel’s SPI oc‑tiny driver allocates the controller with a non‑managed function while registering the interrupt handler with a managed request; during removal the driver unregisters the controller first and then frees it, but the unchecked IRQ handler release is postponed until after the .remove() routine returns. Consequently, a late or latched interrupt can be dispatched to tiny_spi_irq() while its dev_id points to already‑freed memory, leading to a kernel memory corruption that can manifest as a crash or, if exploited, as arbitrary code execution. This mismatch between resource allocation and release highlights a classic Use‑after‑Free defect (CWE‑416).
Affected Systems
Any Linux kernel installation that includes the SPI oc‑tiny driver prior to the recent commit is affected; specifically, kernels that use the legacy spi_alloc_host allocation for this driver while the IRQ handler is managed with devm_request_irq. The vulnerability is independent of hardware; any system that loads the oc‑tiny SPI module built against a vulnerable kernel version is at risk.
Risk and Exploitability
The EPSS score is reported as < 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a very low probability of exploitation in the wild. However, because the defect can cause kernel kernel memory corruption, its impact is high if triggered. The likely attack vector involves an interrupt delivered after the driver initiates its removal while the IRQ is still active, a scenario that could be induced by a malicious or malfunctioning SPI peripheral. Given the severity of potential kernel panic or code execution, the vulnerability warrants that it be treated as a high‑priority patch issue.
OpenCVE Enrichment
Debian DLA
Debian DSA