{"id":"CVE-2026-90270","published":"2026-09-17T17:17:23.573","lastModified":"2026-09-17T17:17:23.573","description":"In the Linux kernel, the following vulnerability has been resolved:\n\narm_mpam: Disable driver unbind to avoid UAF\n\nWhen a user unbinds an MSC and that MSC is the only MSC left for a\ncomponent then the corresponding mpam_component will be freed. If the user\nthen goes on to read the schemata file in the resctrl filesystem then the\nmpam_component will be accessed from resctrl_arch_get_config() leading to a\nuse after free.\n\nAs the MPAM driver is not a module the unbind sysfs interface is the only\nway to trigger the remove. Instead of dealing with the complexity of\nallowing some unused MSC to unbind just remove the unbind sysfs interface.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/7d199b6a0651abad3ca6d0877dbedbe8fe6ea9e2","tags":[]},{"url":"https://git.kernel.org/stable/c/bb1a0f582d519c0461b0940116e2b52c5ba31459","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}