Impact
The disclosure describes a NULL pointer dereference in the arm_mpam driver when an MSC is unbound after mpam_disable() has executed due to an error interrupt. The bug causes the kernel to dereference a NULL pointer, leading to a crash and a denial of service. It represents a classic CWE‑476 flaw.
Affected Systems
Affected systems are all Linux kernels that include the arm_mpam module without the recent patch. The vendor, the Linux kernel project, has updated the driver in the commits referenced in the advisories. No specific version numbers are listed in the provided data, so any kernel build that has not integrated the commit is potentially vulnerable.
Risk and Exploitability
The EPSS score of less than 1% and the absence from the CISA KEV catalog suggest that this issue is not widely exploited. An attacker would need to trigger an error interrupt in the MPAM subsystem and then unbind the MSC, a scenario that normally requires local kernel privilege or root access. Therefore the overall risk is low to moderate, with the primary consequence being a system crash.
OpenCVE Enrichment