PT-2026-98791 · Linux · Linux
CVE-2026-98129
·
Published
2026-09-25
·
Updated
2026-09-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
scsi: mpi3mr: Fix NULL pointer dereference in mpi3mr sas port add()
sas port alloc num() can return NULL on memory allocation failure. The
return value is passed directly to sas port add() without a NULL check,
which causes a NULL pointer dereference.
Additionally, if sas port add() fails, the allocated port is not freed
before jumping to out fail, leaking the sas port structure. Call
sas port free() to properly release it.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux