« Volver al listado

CVE-2026-98088

Estado: En análisisSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

scsi: mpt3sas: Avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues()

dev_to_node() can return NUMA_NO_NODE (-1) on systems without NUMA topology information for the PCI device, such as single-socket boards that don't expose device-to-node affinity. Passing -1 directly into cpumask_of_node() indexes node_to_cpumask_map[-1], an out-of-bounds array read caught by UBSAN:

Fall back to cpu_online_mask when no NUMA node is available, rather than assuming dev_to_node() always returns a valid node index.

Detalles técnicos trazas, registros y código del informe original
  UBSAN: array-index-out-of-bounds in arch/x86/include/asm/topology.h:72:28
  index -1 is out of range for type 'cpumask *[1024]'

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98088",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "728bbc6cbff70051813730fb7977f5d99d867e12",
              "lessThan": "f531758ef21ba9a7716148cc290e8d9a110f20d9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "728bbc6cbff70051813730fb7977f5d99d867e12",
              "lessThan": "06a994ad7bbd13714cd45df582389f751531e60c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "728bbc6cbff70051813730fb7977f5d99d867e12",
              "lessThan": "7bcce856c79c1799351e170aec83e018ccf3d044",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "728bbc6cbff70051813730fb7977f5d99d867e12",
              "lessThan": "0a5f7cdb0cb911584720591069065f09c59ec4fc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "728bbc6cbff70051813730fb7977f5d99d867e12",
              "lessThan": "7b23144c3ff6e46d7d4a464b02f8944265684e39",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "728bbc6cbff70051813730fb7977f5d99d867e12",
              "lessThan": "45504e621b7e884abe59f201e093a3eac7fca7fe",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "728bbc6cbff70051813730fb7977f5d99d867e12",
              "lessThan": "e0d26fe176a8db6ccad4ab38c5bab29391c1946b",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/scsi/mpt3sas/mpt3sas_base.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.3"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.3",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/scsi/mpt3sas/mpt3sas_base.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:38.480",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/06a994ad7bbd13714cd45df582389f751531e60c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/0a5f7cdb0cb911584720591069065f09c59ec4fc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/45504e621b7e884abe59f201e093a3eac7fca7fe",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7b23144c3ff6e46d7d4a464b02f8944265684e39",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7bcce856c79c1799351e170aec83e018ccf3d044",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e0d26fe176a8db6ccad4ab38c5bab29391c1946b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f531758ef21ba9a7716148cc290e8d9a110f20d9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Undergoing Analysis",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: mpt3sas: Avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues()\n\ndev_to_node() can return NUMA_NO_NODE (-1) on systems without NUMA\ntopology information for the PCI device, such as single-socket boards\nthat don't expose device-to-node affinity. Passing -1 directly into\ncpumask_of_node() indexes node_to_cpumask_map[-1], an out-of-bounds\narray read caught by UBSAN:\n\n  UBSAN: array-index-out-of-bounds in arch/x86/include/asm/topology.h:72:28\n  index -1 is out of range for type 'cpumask *[1024]'\n\nFall back to cpu_online_mask when no NUMA node is available, rather than\nassuming dev_to_node() always returns a valid node index."
    }
  ],
  "lastModified": "2026-10-03T11:18:30.453",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}