← All Advisories

CVE-2026-98128

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-98128

Key Details

CVECVE-2026-98128
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

scsi: mpi3mr: Fix target device refcount leak in mpi3mr_sas_port_add()

mpi3mr_get_tgtdev_by_addr() increments the target device kref when it

returns a device. If a subsequent error triggers a goto out_fail after

the tgtdev reference is acquired, the reference is never released

because the out_fail path does not call mpi3mr_tgtdev_put(). This

prevents the target device structure from ever being freed.

Add a tgtdev put in the out_fail path, guarded by a NULL check since

tgtdev is only acquired for SAS_END_DEVICE types and the same cleanup

path is shared by earlier error cases where tgtdev is still NULL. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-98128
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-98128