Description
In the Linux kernel, the following vulnerability has been resolved:

scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup()

The memory allocated for mboxq using mempool_alloc() is not freed in
some of the early exit error paths. Fix that by moving the
mempool_free() call to an earlier point after last use.
Published: 2026-08-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In the Linux kernel’s lpfc SCSI driver, memory allocated for the mailbox queue (mboxq) via mempool_alloc() is not freed during some early exit error paths in the driver_resource_setup() routine. The unchecked allocation leads to a memory leak that can gradually consume kernel memory. While the flaw does not allow direct code execution or privilege escalation, the accumulated loss of memory can degrade performance and, over time, trigger a kernel out‑of‑memory condition or a denial‑of‑service of the system.

Affected Systems

Any Linux kernel that includes the lpfc driver and has not yet incorporated the Git commit adding the missing mempool_free() call is vulnerable. This includes all shipping kernel versions containing that driver until the update is applied. The advisory does not list a specific suite of releases, so all unpatched lpfc implementations are at risk.

Risk and Exploitability

The CVSS score is 5.5 and the EPSS score is less than 1%, and the vulnerability is not listed in CISA KEV. The lack of known public exploits suggests a low immediate threat, but the behaviour can be triggered repeatedly by error paths in resource setup. Based on the description, it is inferred that an attacker with the ability to send SCSI commands or otherwise provoke an error in the lpfc initiator could provoke the memory leak. Over time, an attacker could exhaust kernel memory, leading to a kernel panic or forced reboot, effectively causing a denial‑of‑service. The moderate severity and low probability of exploitation result in a moderate risk that escalates with persistent use.

Generated by OpenCVE AI on August 18, 2026 at 05:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the lpfc driver patch for the missing mempool_free() call.
  • If an immediate kernel upgrade is not possible, unload or blacklist the lpfc module to halt the unnecessary memory allocation.
  • Monitor kernel logs for resource‑setup failures and keep an eye on overall memory utilisation to detect signs of the leak.

Generated by OpenCVE AI on August 18, 2026 at 05:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 23 Aug 2026 13:15:00 +0000


Tue, 18 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-399
CWE-401

Tue, 18 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Low


Sat, 15 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-399
CWE-401

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup() The memory allocated for mboxq using mempool_alloc() is not freed in some of the early exit error paths. Fix that by moving the mempool_free() call to an earlier point after last use.
Title scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-23T12:46:47.317Z

Reserved: 2026-08-09T03:40:39.905Z

Link: CVE-2026-72087

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:21:22.723

Modified: 2026-08-23T13:16:39.890

Link: CVE-2026-72087

cve-icon Redhat

Severity : Low

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72087 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T05:45:03Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime