Impact
The vulnerability originates in the Linux kernel MPAM driver, which manages memory system controllers. When a system administrator unbinds the last remaining MSC attached to a component through the sysfs unbind interface, the kernel prematurely frees the associated mpam_component structure. Subsequent reads of the resctrl schemata file invoke resctrl_arch_get_config(), which dereferences the freed structure, leading to a kernel use‑after‑free. This flaw is a classic example of use‑after‑free (CWE‑416).
Affected Systems
The affected product is the generic Linux kernel; the flaw is present in the built‑in MPAM driver regardless of kernel version because the patch removes the unbind sysfs entry. No specific kernel releases are enumerated in the advisory, so all kernels exposing this interface are potentially impacted.
Risk and Exploitability
The EPSS score is reported as less than 1 % and the vulnerability is not listed in CISA KEV, suggesting it is not widely exploited yet. The flaw can be triggered by a local user with sufficient permission to write to the MPAM unbind sysfs entry. Based on the description, it is inferred that a local privileged user (e.g., root or a user with write access to the sysfs interface) can perform the exploit. Because no CVSS score is offered, the exact severity cannot be quantified, but a use‑after‑free in kernel space typically indicates a high‑severity risk.
OpenCVE Enrichment