Database/Kernel, userspace & hypervisor
Linux kernel mpi3mr: NULL dereference and sas_port leak when SAS port allocation fails
Impact
mpi3mr_sas_port_add() passes the result of sas_port_alloc_num() straight into sas_port_add() without checking for NULL, so an allocation failure during SAS topology discovery dereferences NULL and takes down the kernel. The same path leaks the allocated sas_port when sas_port_add() fails. mpi3mr drives Broadcom tri-mode HBAs and RAID controllers that sit under local NVMe and SAS storage on many GPU server platforms, so the crash lands on the storage path of a node that is expensive to drain. There is no attacker-controlled input here: it is reached only under memory pressure or on device probe and hotplug, which makes this a stability and availability fix rather than a privilege boundary one. Rate it accordingly when deciding whether it justifies a window.
Who can reach it
Local, no authenticated actor required and none sufficient on its own - the failing path needs a kernel allocation failure during HBA probe or SAS device hotplug. Not reachable from a tenant pod or over the network.
What to do
Pick up the stable-kernel fix (NULL check plus sas_port_free() on the failure path) from the linked commits in your maintained branch. That means a kernel upgrade and a reboot of each affected node; given there is no attacker-controlled trigger, it is reasonable to fold into the next routine kernel roll rather than open an out-of-band window. The record carries no vendor advisory or fixed release numbers.
References
Related entries
- Linux cgroup: task iterator can resurrect a zero-refcount dying task, giving a use-after-freeCVE-2026-98163 · Linux kernel cgroup task iterator (css_task_iter_next over dying_tasks)Unscored
- Linux KVM x86/mmu: write tracking checked in one address space only, reaching a kernel BUGCVE-2026-98164 · Linux kernel KVM x86/mmu (kvm_gfn_is_write_tracked across address spaces)Unscored
- Microsoft Hyper-V: vmswitch fails to validate guest OID requestsCVE-2021-28476 · Microsoft Hyper-VCritical
- Incus: instance snapshots bypass restricted.containers.lowlevel, giving command execution on the hostCVE-2026-48751 · Incus (instance snapshots ignore restricted.containers.lowlevel)Critical
- VMware ESXi (OpenSLP): Use-after-free in OpenSLP on port 427 - unauthenticated remote code execution on the hypervisorCVE-2020-3992 · VMware ESXi (OpenSLP)Critical
- Linux kernel mlx5_core kTLS RX offload: TLS RX resync list corruption: entries are moved by the resync handlerCVE-2021-47215 · Linux kernel mlx5_core kTLS RX offloadCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.