CVE-2026-98088 PUBLISHED

scsi: mpt3sas: Avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues()

Assigner: Linux
Reserved: 25.09.2026 Published: 25.09.2026 Updated: 25.09.2026

In the Linux kernel, the following vulnerability has been resolved:

scsi: mpt3sas: Avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues()

dev_to_node() can return NUMA_NO_NODE (-1) on systems without NUMA topology information for the PCI device, such as single-socket boards that don't expose device-to-node affinity. Passing -1 directly into cpumask_of_node() indexes node_to_cpumask_map[-1], an out-of-bounds array read caught by UBSAN:

UBSAN: array-index-out-of-bounds in arch/x86/include/asm/topology.h:72:28 index -1 is out of range for type 'cpumask *[1024]'

Fall back to cpu_online_mask when no NUMA node is available, rather than assuming dev_to_node() always returns a valid node index.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 728bbc6cbff70051813730fb7977f5d99d867e12 to 0a5f7cdb0cb911584720591069065f09c59ec4fc (excl.)
  • affected from 728bbc6cbff70051813730fb7977f5d99d867e12 to 7b23144c3ff6e46d7d4a464b02f8944265684e39 (excl.)
  • affected from 728bbc6cbff70051813730fb7977f5d99d867e12 to 45504e621b7e884abe59f201e093a3eac7fca7fe (excl.)
  • affected from 728bbc6cbff70051813730fb7977f5d99d867e12 to e0d26fe176a8db6ccad4ab38c5bab29391c1946b (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 5.3 is affected
  • unaffected from 0 to 5.3 (excl.)
  • unaffected from 6.12.111 to 6.12.* (incl.)
  • unaffected from 6.18.53 to 6.18.* (incl.)
  • unaffected from 7.2.7 to 7.2.* (incl.)
  • unaffected from 7.3-rc2 to * (incl.)

References