Skip to main content
Vulnerability Database/CVE-2026-98088

CVE-2026-98088: Linux Kernel Buffer Overflow Vulnerability

CVE-2026-98088 is a buffer overflow flaw in the Linux kernel SCSI mpt3sas driver that causes out-of-bounds array access on systems without NUMA topology. This post covers technical details, affected versions, and mitigation.

Published:

CVE-2026-98088 Overview

CVE-2026-98088 is an out-of-bounds array read in the Linux kernel's mpt3sas SCSI driver. The flaw resides in _base_assign_reply_queues(), where dev_to_node() can return NUMA_NO_NODE (-1) on systems without NUMA topology information for the PCI device. Passing -1 directly into cpumask_of_node() indexes node_to_cpumask_map[-1], triggering an out-of-bounds read detected by the Undefined Behavior Sanitizer (UBSAN). Single-socket systems that do not expose device-to-node affinity are particularly affected. The kernel maintainers resolved the issue by falling back to cpu_online_mask when no valid NUMA node is available.

Critical Impact

An out-of-bounds read in a core SCSI driver may cause undefined kernel behavior, memory disclosure, or system instability on affected hardware configurations.

Affected Products

  • Linux kernel versions containing the pre-patch mpt3sas driver implementation
  • Systems using Broadcom/LSI MPT Fusion SAS host bus adapters managed by mpt3sas
  • Single-socket hardware platforms lacking NUMA device-to-node affinity information

Discovery Timeline

  • 2026-09-25 - CVE-2026-98088 published to NVD
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-98088

Vulnerability Analysis

The vulnerability is an out-of-bounds read [CWE-125] in the _base_assign_reply_queues() function of the mpt3sas SCSI driver. During reply queue assignment, the driver queries the NUMA node of the underlying PCI device using dev_to_node(). The returned value is passed unchecked to cpumask_of_node(), which indexes the node_to_cpumask_map array. When the PCI device has no associated NUMA node, dev_to_node() returns NUMA_NO_NODE, defined as -1. The negative index causes an array access outside the declared cpumask *[1024] bounds, which UBSAN explicitly flags at arch/x86/include/asm/topology.h:72:28.

Root Cause

The root cause is a missing validation check between dev_to_node() and cpumask_of_node(). The driver assumed that every PCI device would report a valid NUMA node index. On single-socket boards and systems that do not expose device-to-node affinity, this assumption fails. The resulting negative array index produces undefined behavior under the C standard and reads memory immediately before the node_to_cpumask_map array.

Attack Vector

The condition triggers automatically during driver initialization on affected hardware, not through a remote attacker action. Impact is limited to local systems that load the mpt3sas driver against supported SAS controllers under non-NUMA or NUMA-less PCI configurations. The out-of-bounds read may surface as kernel warnings, incorrect reply queue affinity, or latent memory corruption depending on adjacent memory contents.

No verified exploitation code is available. The upstream fix replaces the unchecked path with a fallback to cpu_online_mask when dev_to_node() does not return a valid node, as documented in the kernel stable commits.

Detection Methods for CVE-2026-98088

Indicators of Compromise

  • UBSAN warnings in dmesg referencing array-index-out-of-bounds in arch/x86/include/asm/topology.h
  • Kernel log entries citing index -1 is out of range for type 'cpumask *[1024]'
  • mpt3sas driver initialization messages followed by abnormal interrupt or queue affinity behavior

Detection Strategies

  • Audit running kernel versions against the fixed commits (0a5f7cd, 45504e6, 7b23144, e0d26fe)
  • Enable UBSAN in test and staging kernels to surface the out-of-bounds access during driver load
  • Inventory hosts using LSI/Broadcom SAS HBAs on single-socket boards to prioritize patching

Monitoring Recommendations

  • Forward kernel ring buffer logs to a centralized log platform and alert on UBSAN or mpt3sas warnings
  • Track package versions for the kernel across Linux fleets and flag hosts still on vulnerable builds
  • Monitor for storage subsystem errors or interrupt affinity anomalies on affected hardware

How to Mitigate CVE-2026-98088

Immediate Actions Required

  • Identify Linux hosts running the mpt3sas driver with supported Broadcom/LSI SAS controllers
  • Apply the vendor-supplied kernel update that includes the fallback to cpu_online_mask
  • Schedule reboots on affected production hosts after validating the patched kernel in a test environment

Patch Information

The upstream fix adds a validation step: if dev_to_node() returns NUMA_NO_NODE, the driver uses cpu_online_mask instead of indexing node_to_cpumask_map with a negative value. The patch is available in the stable kernel tree across the following commits: 0a5f7cd, 45504e6, 7b23144, and e0d26fe. Consume the fix through the distribution kernel package where possible.

Workarounds

  • Blacklist the mpt3sas module on hosts that do not require the affected SAS controllers
  • Use alternative storage controllers or kernel builds that already contain the fix on single-socket systems
  • Where patching is delayed, isolate affected hosts and monitor kernel logs for UBSAN activity until the update can be applied

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.