Medium severity5.5NVD Advisory· Published Jun 26, 2026· Updated Jul 8, 2026
CVE-2026-53278
CVE-2026-53278
Description
In the Linux kernel, the following vulnerability has been resolved:
arm_mpam: Check whether the config array is allocated before destroying it
__destroy_component_cfg() is called to free the configuration array. It uses the embedded 'garbage' structure, which means the array has to be allocated.
If __destroy_component_cfg() is called from mpam_disable() before the configuration was ever allocated, then a NULL pointer is dereferenced.
Check for this case and return early if the configuration is not allocated.
__destroy_component_cfg() also frees the mbwu_state as this is allocated by __allocate_component_cfg(). As the mbwu_state is allocated after comp->cfg is set, and is also under mpam_list_lock, only the first pointer needs checking.
Affected products
6Patches
Vulnerability mechanics
References
2News mentions
1- Linux Kernel: 25 Vulnerabilities Affecting Networking, Graphics, and Memory Management Disclosed TogetherVypr Intelligence · Jun 27, 2026