CVE-2026-98129: Linux
EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Fix NULL pointer dereference in mpi3mr_sas_port_add() sas_port_alloc_num() can return NULL on memory allocation failure. The return value is passed directly to sas_port_add() without a NULL check, which causes a NULL pointer dereference. Additionally, if sas_port_add() fails, the allocated port is not freed before jumping to out_fail, leaking the sas_port structure. Call sas_port_free() to properly release it.
Affected products
- Linux Linux: from 6.1, before 6.1.189 (fixed in 6.1.189); from 6.2, before 6.6.158 (fixed in 6.6.158); from 6.7, before 6.12.111 (fixed in 6.12.111); from 6.13, before 6.18.53 (fixed in 6.18.53); from 6.19, before 7.2.7 (fixed in 7.2.7)
Published 2026-09-25. Last modified 2026-10-03.