CVE-2026-68345

Summary

In the Linux kernel, the following vulnerability has been resolved:

arm_mpam: guard MBWU state before adding it to garbage

__destroy_component_cfg() adds each RIS mbwu_state object to the MPAM garbage list when destroying component configuration.

However, mbwu_state is allocated per RIS and only for RISes with MBWU monitors. A component can therefore have comp->cfg allocated while some RISes still have ris->mbwu_state set to NULL.

Passing a NULL mbwu_state to add_to_garbage() dereferences the NULL pointer inside the macro.

Skip RISes that do not have an mbwu_state object before adding them to the garbage list.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux41e8a14950e1732af51cfec8fa09f8ded02a5ca9 < ca1f96334267ab8d47b2c9d535cdc9920fdde269affected
LinuxLinux41e8a14950e1732af51cfec8fa09f8ded02a5ca9 < 977f52909c624210178a1247fab0b02b110c1106affected
LinuxLinux6.19affected
LinuxLinux0 < 6.19unaffected
LinuxLinux7.1.6 <= 7.1.*unaffected
LinuxLinux7.2-rc5 <= *unaffected

Weaknesses

References