Description
In the Linux kernel, the following vulnerability has been resolved:

scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers

_base_release_memory_pools() unconditionally frees every
ioc->pcie_sg_lookup[] entry, including ones the setup loop never
allocated after a partial failure, causing a "bad dma" warning on debug
kernels or a NULL pointer dereference otherwise.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel crash causing denial of service
Action: Apply patch
AI Analysis

Impact

The bug resides in the Linux kernel's SCSI mpt3sas driver. During a partial failure of the PCIe SGL buffer setup, the release function unconditionally frees entries that were never allocated. This results in a NULL pointer dereference, which manifests as a bad DMA warning during debugging or a kernel panic on a production system.

Affected Systems

The vulnerability exists in the Linux kernel on all releases that include the unpatched mpt3sas driver. No explicit version range is supplied, but any kernel before the patch corresponding to the commits referenced in the advisory is affected. The vendor is the Linux kernel maintainer and the product is the kernel itself.

Risk and Exploitability

The EPSS score of less than 1% indicates a very low probability that the vulnerability will be exploited in the wild. The issue is not currently listed in the CISA KEV catalog, and no known exploits have been reported. The likely attack vector requires local or device-level access to the SCSI subsystem; based on the description, it is inferred that the vulnerability can be triggered by a failure in the SCSI driver's buffer allocation routine. The severity is high due to the potential for a kernel-level crash, but the lack of active exploitation mitigates immediate risk.

Generated by OpenCVE AI on September 20, 2026 at 01:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version where the patch is incorporated
  • Apply the kernel patch that corrects the SGL buffer free logic (if using a custom kernel or backport)
  • If an immediate kernel update is not possible, disable or unload the mpt3sas driver temporarily to prevent the vulnerable code from executing

Generated by OpenCVE AI on September 20, 2026 at 01:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers _base_release_memory_pools() unconditionally frees every ioc->pcie_sg_lookup[] entry, including ones the setup loop never allocated after a partial failure, causing a "bad dma" warning on debug kernels or a NULL pointer dereference otherwise.
Title scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:19.514Z

Reserved: 2026-09-11T19:38:34.792Z

Link: CVE-2026-90202

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:15.180

Modified: 2026-09-17T17:17:15.180

Link: CVE-2026-90202

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:30:16Z

Weaknesses