CVE-2026-98128 is a vulnerability in Linux Kernel
Published on September 25, 2026
scsi: mpi3mr: Fix target device refcount leak in mpi3mr_sas_port_add()
In the Linux kernel, the following vulnerability has been resolved:
scsi: mpi3mr: Fix target device refcount leak in mpi3mr_sas_port_add()
mpi3mr_get_tgtdev_by_addr() increments the target device kref when it
returns a device. If a subsequent error triggers a goto out_fail after
the tgtdev reference is acquired, the reference is never released
because the out_fail path does not call mpi3mr_tgtdev_put(). This
prevents the target device structure from ever being freed.
Add a tgtdev put in the out_fail path, guarded by a NULL check since
tgtdev is only acquired for SAS_END_DEVICE types and the same cleanup
path is shared by earlier error cases where tgtdev is still NULL.
Products Associated with CVE-2026-98128
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version e22bae30667a7e74ed057e00fb6e8c79e0738de3 and below 040146f81d099006a354b0caacc7f01ca00f257e is affected.
- Version e22bae30667a7e74ed057e00fb6e8c79e0738de3 and below 06a7073b33b8f5cb0ee71e07dc669efffb1c7d58 is affected.
- Version e22bae30667a7e74ed057e00fb6e8c79e0738de3 and below 1ccbe8c42009706af79e6629c70d42fc929aef2b is affected.
- Version e22bae30667a7e74ed057e00fb6e8c79e0738de3 and below 419d129f970aaa6567dbac366b0c93784bf9ec97 is affected.
- Version 6.1 is affected.
- Before 6.1 is unaffected.
- Version 6.12.111, <= 6.12.* is unaffected.
- Version 6.18.53, <= 6.18.* is unaffected.
- Version 7.2.7, <= 7.2.* is unaffected.
- Version 7.3-rc2, <= * is unaffected.