{"id":"CVE-2026-90270","title":"In the Linux kernel, the following vulnerability has been resolved:\n\narm_mpam: Disable driver unbind to avoid UAF\n\nWhen a user unbinds an MSC and that MSC is the only MSC left for a\ncomponent then the corresponding mpam_component will be…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\narm_mpam: Disable driver unbind to avoid UAF\n\nWhen a user unbinds an MSC and that MSC is the only MSC left for a\ncomponent then the corresponding mpam_component will be…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= f04046f2577a5c76167333ca99d3903ee5331ba0 < 7d199b6a0651abad3ca6d0877dbedbe8fe6ea9e2","Linux >= f04046f2577a5c76167333ca99d3903ee5331ba0 < bb1a0f582d519c0461b0940116e2b52c5ba31459","Linux 6.19"],"published":"2026-09-17","updated":"2026-09-17","sourceUpdated":"2026-09-17T17:17:23.573","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90270","references":[{"url":"https://git.kernel.org/stable/c/7d199b6a0651abad3ca6d0877dbedbe8fe6ea9e2","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bb1a0f582d519c0461b0940116e2b52c5ba31459","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-17T16:21:47.838Z","epss":0.00198,"epssPercentile":0.08482,"slug":"CVE-2026-90270","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\narm_mpam: Disable driver unbind to avoid UAF\n\nWhen a user unbinds an MSC and that MSC is the only MSC left for a\ncomponent then the corresponding mpam_component will be freed. If the user\nthen goes on to read the schemata file in the resctrl filesystem then the\nmpam_component will be accessed from resctrl_arch_get_config() leading to a\nuse after free.\n\nAs the MPAM driver is not a module the unbind sysfs interface is the only\nway to trigger the remove. Instead of dealing with the complexity of\nallowing some unused MSC to unbind just remove the unbind sysfs interface.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}