CVE-2026-68345 PUBLISHED

arm_mpam: guard MBWU state before adding it to garbage

Assigner: Linux
Reserved: 30.07.2026 Published: 10.08.2026 Updated: 10.08.2026

In the Linux kernel, the following vulnerability has been resolved:

arm_mpam: guard MBWU state before adding it to garbage

__destroy_component_cfg() adds each RIS mbwu_state object to the MPAM garbage list when destroying component configuration.

However, mbwu_state is allocated per RIS and only for RISes with MBWU monitors. A component can therefore have comp->cfg allocated while some RISes still have ris->mbwu_state set to NULL.

Passing a NULL mbwu_state to add_to_garbage() dereferences the NULL pointer inside the macro.

Skip RISes that do not have an mbwu_state object before adding them to the garbage list.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 41e8a14950e1732af51cfec8fa09f8ded02a5ca9 to ca1f96334267ab8d47b2c9d535cdc9920fdde269 (excl.)
  • affected from 41e8a14950e1732af51cfec8fa09f8ded02a5ca9 to 977f52909c624210178a1247fab0b02b110c1106 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.19 is affected
  • unaffected from 0 to 6.19 (excl.)
  • unaffected from 7.1.6 to 7.1.* (incl.)
  • unaffected from 7.2-rc5 to * (incl.)

References