Impact
The bug resides in the Linux kernel's SCSI mpt3sas driver. During a partial failure of the PCIe SGL buffer setup, the release function unconditionally frees entries that were never allocated. This results in a NULL pointer dereference, which manifests as a bad DMA warning during debugging or a kernel panic on a production system.
Affected Systems
The vulnerability exists in the Linux kernel on all releases that include the unpatched mpt3sas driver. No explicit version range is supplied, but any kernel before the patch corresponding to the commits referenced in the advisory is affected. The vendor is the Linux kernel maintainer and the product is the kernel itself.
Risk and Exploitability
The EPSS score of less than 1% indicates a very low probability that the vulnerability will be exploited in the wild. The issue is not currently listed in the CISA KEV catalog, and no known exploits have been reported. The likely attack vector requires local or device-level access to the SCSI subsystem; based on the description, it is inferred that the vulnerability can be triggered by a failure in the SCSI driver's buffer allocation routine. The severity is high due to the potential for a kernel-level crash, but the lack of active exploitation mitigates immediate risk.
OpenCVE Enrichment
Debian DLA
Debian DSA