NONE · 0

CVE-2026-68345

In the Linux kernel, the following vulnerability has been resolved: arm_mpam: guard MBWU state before adding it to garbage __destroy_component_cfg() adds each RIS mbwu_state object to the MPAM garba...

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved: arm_mpam: guard MBWU state before adding it to garbage __destroy_component_cfg() adds each RIS mbwu_state object to the MPAM garbage list when destroying component configuration. However, mbwu_state is allocated per RIS and only for RISes with MBWU monitors. A component can therefore have comp->cfg allocated while some RISes still have ris->mbwu_state set to NULL. Passing a NULL mbwu_state to add_to_garbage() dereferences the NULL pointer inside the macro. Skip RISes that do not have an mbwu_state object before adding them to the garbage list.

References

FAQ

What is CVE-2026-68345?

CVE-2026-68345 is a documented vulnerability. In the Linux kernel, the following vulnerability has been resolved: arm_mpam: guard MBWU state before adding it to garbage __destroy_component_cfg() adds each RIS mbwu_state object to the MPAM garba...

How severe is CVE-2026-68345?

CVSS scoring is not yet available for CVE-2026-68345. Check NVD for updates.

Is there a patch for CVE-2026-68345?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.