Database/Kernel, userspace & hypervisor
Linux kernel mpi3mr: error path in mpi3mr_sas_port_add() leaks a target device reference
Impact
mpi3mr_get_tgtdev_by_addr() takes a kref on the target device it returns. If a later error sends control to the out_fail path, that path never called mpi3mr_tgtdev_put(), so the reference is never released and the target device structure can never be freed. The result is a slow kernel memory leak on nodes using Broadcom MPI3-generation storage controllers, accumulating one leaked target device per failed SAS port add - a resource exhaustion and stale-object concern over long uptimes, not an attacker-controlled memory-safety bug. Matters most on long-lived GPU and HPC nodes with attached SAS storage, where reboots are expensive and uptimes are measured in months.
Who can reach it
No attacker interaction: the leak happens when SAS port addition fails during device discovery on affected hardware. Not reachable by a tenant or remote party.
What to do
Update to a stable kernel where the out_fail path puts the tgtdev under a NULL check (the reference is only taken for SAS_END_DEVICE types, and earlier error cases share the path with tgtdev still NULL). The fix is in the HBA driver and takes effect at module load or boot, so it needs a node reboot after drain; there is no mitigation other than avoiding the discovery failures that trigger it.
References
Related entries
- Linux kernel mpi3mr: NULL dereference and sas_port leak when SAS port allocation failsCVE-2026-98129 · Linux kernel mpi3mr (Broadcom tri-mode SAS/SATA/NVMe HBA driver)Unscored
- Linux cgroup: task iterator can resurrect a zero-refcount dying task, giving a use-after-freeCVE-2026-98163 · Linux kernel cgroup task iterator (css_task_iter_next over dying_tasks)Unscored
- Linux KVM x86/mmu: write tracking checked in one address space only, reaching a kernel BUGCVE-2026-98164 · Linux kernel KVM x86/mmu (kvm_gfn_is_write_tracked across address spaces)Unscored
- Microsoft Hyper-V: vmswitch fails to validate guest OID requestsCVE-2021-28476 · Microsoft Hyper-VCritical
- Incus: instance snapshots bypass restricted.containers.lowlevel, giving command execution on the hostCVE-2026-48751 · Incus (instance snapshots ignore restricted.containers.lowlevel)Critical
- VMware ESXi (OpenSLP): Use-after-free in OpenSLP on port 427 - unauthenticated remote code execution on the hypervisorCVE-2020-3992 · VMware ESXi (OpenSLP)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.