Description
In the Linux kernel, the following vulnerability has been resolved:

arm_mpam: Fix a NULL pointer dereference on unbinding after an error interrupt

If a user unbinds an MSC after mpam_disable() has been run in response
to an error interrupt then a dereference of a NULL pointer occurs as
mpam_disable() sets the drvdata to NULL. Add an early return to the driver
remove callback to avoid this.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Crash / Denial of Service
Action: Patch Kernel
AI Analysis

Impact

The disclosure describes a NULL pointer dereference in the arm_mpam driver when an MSC is unbound after mpam_disable() has executed due to an error interrupt. The bug causes the kernel to dereference a NULL pointer, leading to a crash and a denial of service. It represents a classic CWE‑476 flaw.

Affected Systems

Affected systems are all Linux kernels that include the arm_mpam module without the recent patch. The vendor, the Linux kernel project, has updated the driver in the commits referenced in the advisories. No specific version numbers are listed in the provided data, so any kernel build that has not integrated the commit is potentially vulnerable.

Risk and Exploitability

The EPSS score of less than 1% and the absence from the CISA KEV catalog suggest that this issue is not widely exploited. An attacker would need to trigger an error interrupt in the MPAM subsystem and then unbind the MSC, a scenario that normally requires local kernel privilege or root access. Therefore the overall risk is low to moderate, with the primary consequence being a system crash.

Generated by OpenCVE AI on September 19, 2026 at 04:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version that includes the arm_mpam NULL pointer dereference fix, as noted in the referenced commits.
  • If an immediate kernel upgrade is not possible, avoid unbinding MSCs after an error interrupt until the system is patched; defer or delay unbinding or re‑enable the device before unbinding.
  • Apply the exact upstream patch from the commit identifiers a29044c9c83513c7463de2adb84c169685562ad2 or fc996c39689bb15aa80e5366809434f7258fb703 if the vendor has not yet released a stable update.
  • Monitor kernel release notes for the arm_mpam driver for a formal security release and apply promptly.

Generated by OpenCVE AI on September 19, 2026 at 04:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: arm_mpam: Fix a NULL pointer dereference on unbinding after an error interrupt If a user unbinds an MSC after mpam_disable() has been run in response to an error interrupt then a dereference of a NULL pointer occurs as mpam_disable() sets the drvdata to NULL. Add an early return to the driver remove callback to avoid this.
Title arm_mpam: Fix a NULL pointer dereference on unbinding after an error interrupt
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:05.304Z

Reserved: 2026-09-11T19:38:34.797Z

Link: CVE-2026-90271

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:23.677

Modified: 2026-09-17T17:17:23.677

Link: CVE-2026-90271

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T04:30:16Z

Weaknesses