GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux kernel mpt3sas: NUMA_NO_NODE from dev_to_node() causes an out-of-bounds node_to_cpumask_map read

UnscoredCVE-2026-98088Kernel, userspace & hypervisorcurated

Impact

dev_to_node() can return NUMA_NO_NODE (-1) when the platform exposes no device-to-node affinity for the PCI device, such as single-socket boards. mpt3sas passed that value straight into cpumask_of_node(), indexing node_to_cpumask_map[-1] - an out-of-bounds array read that UBSAN flags as array-index-out-of-bounds in arch/x86/include/asm/topology.h. The practical effect is an out-of-bounds read at HBA probe time, which can mean garbage reply-queue CPU affinity or a fault during initialization of the storage controller on a node; the record does not claim anything beyond the bad read. Relevant to GPU and HPC nodes that use Broadcom/LSI SAS HBAs for local or JBOD storage, and only on systems where the firmware does not report NUMA affinity for the device.

Who can reach it

No attacker interaction: the bad index is taken during driver probe on affected hardware/firmware configurations. Not remotely or locally triggerable by an unprivileged user.

What to do

Update to a stable kernel where the driver falls back to cpu_online_mask when no NUMA node is available instead of assuming dev_to_node() returns a valid index. The fix is in the HBA driver, so it takes effect at module load or boot - plan a node reboot after draining the node. No firmware change is required and no mitigation is described.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.