NULL pointer dereference in Linux kernel - CVE-2026-90271
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in the arm_mpam driver remove callback when unbinding an MSC after mpam_disable() runs in response to an error interrupt. A local user can unbind an MSC after an error interrupt to cause a denial of service.