Database/Kernel, userspace & hypervisor
Linux kernel mpt3sas: NUMA_NO_NODE from dev_to_node() causes an out-of-bounds node_to_cpumask_map read
Impact
dev_to_node() can return NUMA_NO_NODE (-1) when the platform exposes no device-to-node affinity for the PCI device, such as single-socket boards. mpt3sas passed that value straight into cpumask_of_node(), indexing node_to_cpumask_map[-1] - an out-of-bounds array read that UBSAN flags as array-index-out-of-bounds in arch/x86/include/asm/topology.h. The practical effect is an out-of-bounds read at HBA probe time, which can mean garbage reply-queue CPU affinity or a fault during initialization of the storage controller on a node; the record does not claim anything beyond the bad read. Relevant to GPU and HPC nodes that use Broadcom/LSI SAS HBAs for local or JBOD storage, and only on systems where the firmware does not report NUMA affinity for the device.
Who can reach it
No attacker interaction: the bad index is taken during driver probe on affected hardware/firmware configurations. Not remotely or locally triggerable by an unprivileged user.
What to do
Update to a stable kernel where the driver falls back to cpu_online_mask when no NUMA node is available instead of assuming dev_to_node() returns a valid index. The fix is in the HBA driver, so it takes effect at module load or boot - plan a node reboot after draining the node. No firmware change is required and no mitigation is described.
References
Related entries
- Linux kernel mpi3mr: error path in mpi3mr_sas_port_add() leaks a target device referenceCVE-2026-98128 · Linux kernel mpi3mr (target device refcount leak in mpi3mr_sas_port_add())Unscored
- Linux kernel mpi3mr: NULL dereference and sas_port leak when SAS port allocation failsCVE-2026-98129 · Linux kernel mpi3mr (Broadcom tri-mode SAS/SATA/NVMe HBA driver)Unscored
- Linux cgroup: task iterator can resurrect a zero-refcount dying task, giving a use-after-freeCVE-2026-98163 · Linux kernel cgroup task iterator (css_task_iter_next over dying_tasks)Unscored
- Linux KVM x86/mmu: write tracking checked in one address space only, reaching a kernel BUGCVE-2026-98164 · Linux kernel KVM x86/mmu (kvm_gfn_is_write_tracked across address spaces)Unscored
- Microsoft Hyper-V: vmswitch fails to validate guest OID requestsCVE-2021-28476 · Microsoft Hyper-VCritical
- Incus: instance snapshots bypass restricted.containers.lowlevel, giving command execution on the hostCVE-2026-48751 · Incus (instance snapshots ignore restricted.containers.lowlevel)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.