CVE-2026-68345EPSS p9.8%
CVE-2026-68345CVE-2026-68345
Description
In the Linux kernel, the following vulnerability has been resolved:
arm_mpam: guard MBWU state before adding it to garbage
__destroy_component_cfg() adds each RIS mbwu_state object to the MPAM
garbage list when destroying component configuration.
However, mbwu_state is allocated per RIS and only for RISes with MBWU
monitors. A component can therefore have comp->cfg allocated while some
RISes still have ris->mbwu_state set to NULL.
Passing a NULL mbwu_state to add_to_garbage() dereferences the NULL
pointer inside the macro.
Skip RISes that do not have an mbwu_state object before adding them to
the garbage list.
Scoring
| EPSS | 0.20% probability of exploitation · percentile 9.8% · 2026-08-11T12:00:17Z |
| Last modified | 2026-08-10 |