GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux kernel mpi3mr: NULL dereference and sas_port leak when SAS port allocation fails

UnscoredCVE-2026-98129Kernel, userspace & hypervisorcurated

Impact

mpi3mr_sas_port_add() passes the result of sas_port_alloc_num() straight into sas_port_add() without checking for NULL, so an allocation failure during SAS topology discovery dereferences NULL and takes down the kernel. The same path leaks the allocated sas_port when sas_port_add() fails. mpi3mr drives Broadcom tri-mode HBAs and RAID controllers that sit under local NVMe and SAS storage on many GPU server platforms, so the crash lands on the storage path of a node that is expensive to drain. There is no attacker-controlled input here: it is reached only under memory pressure or on device probe and hotplug, which makes this a stability and availability fix rather than a privilege boundary one. Rate it accordingly when deciding whether it justifies a window.

Who can reach it

Local, no authenticated actor required and none sufficient on its own - the failing path needs a kernel allocation failure during HBA probe or SAS device hotplug. Not reachable from a tenant pod or over the network.

What to do

Pick up the stable-kernel fix (NULL check plus sas_port_free() on the failure path) from the linked commits in your maintained branch. That means a kernel upgrade and a reboot of each affected node; given there is no attacker-controlled trigger, it is reasonable to fold into the next routine kernel roll rather than open an out-of-band window. The record carries no vendor advisory or fixed release numbers.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.