linux linux-kernel CVE-2026-98129 is a vulnerability in Linux Kernel
Published on September 25, 2026

scsi: mpi3mr: Fix NULL pointer dereference in mpi3mr_sas_port_add()
In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Fix NULL pointer dereference in mpi3mr_sas_port_add() sas_port_alloc_num() can return NULL on memory allocation failure. The return value is passed directly to sas_port_add() without a NULL check, which causes a NULL pointer dereference. Additionally, if sas_port_add() fails, the allocated port is not freed before jumping to out_fail, leaking the sas_port structure. Call sas_port_free() to properly release it.

NVD


Products Associated with CVE-2026-98129

Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.

 

Affected Versions

Linux: Linux: