GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux kernel mpi3mr: error path in mpi3mr_sas_port_add() leaks a target device reference

UnscoredCVE-2026-98128Kernel, userspace & hypervisorcurated

Impact

mpi3mr_get_tgtdev_by_addr() takes a kref on the target device it returns. If a later error sends control to the out_fail path, that path never called mpi3mr_tgtdev_put(), so the reference is never released and the target device structure can never be freed. The result is a slow kernel memory leak on nodes using Broadcom MPI3-generation storage controllers, accumulating one leaked target device per failed SAS port add - a resource exhaustion and stale-object concern over long uptimes, not an attacker-controlled memory-safety bug. Matters most on long-lived GPU and HPC nodes with attached SAS storage, where reboots are expensive and uptimes are measured in months.

Who can reach it

No attacker interaction: the leak happens when SAS port addition fails during device discovery on affected hardware. Not reachable by a tenant or remote party.

What to do

Update to a stable kernel where the out_fail path puts the tgtdev under a NULL check (the reference is only taken for SAS_END_DEVICE types, and earlier error cases share the path with tgtdev still NULL). The fix is in the HBA driver and takes effect at module load or boot, so it needs a node reboot after drain; there is no mitigation other than avoiding the discovery failures that trigger it.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.