CVE-2026-98129EPSS p6.1%
CVE-2026-98129CVE-2026-98129
Description
In the Linux kernel, the following vulnerability has been resolved:
scsi: mpi3mr: Fix NULL pointer dereference in mpi3mr_sas_port_add()
sas_port_alloc_num() can return NULL on memory allocation failure. The
return value is passed directly to sas_port_add() without a NULL check,
which causes a NULL pointer dereference.
Additionally, if sas_port_add() fails, the allocated port is not freed
before jumping to out_fail, leaking the sas_port structure. Call
sas_port_free() to properly release it.
Scoring
| EPSS | 0.17% probability of exploitation · percentile 6.1% · 2026-10-05T12:00:23Z |
| Last modified | 2026-10-03 |