CVE-2026-68345
N/A
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
arm_mpam: guard MBWU state before adding it to garbage
__destroy_component_cfg() adds each RIS mbwu_state object to the MPAM garbage list when destroying component configuration.
However, mbwu_state is allocated per RIS and only for RISes with MBWU monitors. A component can therefore have comp->cfg allocated while some RISes still have ris->mbwu_state set to NULL.
Passing a NULL mbwu_state to add_to_garbage() dereferences the NULL pointer inside the macro.
Skip RISes that do not have an mbwu_state object before adding them to the garbage list.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 41e8a14950e1732af51cfec8fa09f8ded02a5ca9 < ca1f96334267ab8d47b2c9d535cdc9920fdde269 | affected |
| Linux | Linux | 41e8a14950e1732af51cfec8fa09f8ded02a5ca9 < 977f52909c624210178a1247fab0b02b110c1106 | affected |
| Linux | Linux | 6.19 | affected |
| Linux | Linux | 0 < 6.19 | unaffected |
| Linux | Linux | 7.1.6 <= 7.1.* | unaffected |
| Linux | Linux | 7.2-rc5 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/ca1f96334267ab8d47b2c9d535cdc9920fdde269
- https://git.kernel.org/stable/c/977f52909c624210178a1247fab0b02b110c1106
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.