Answer in brief
CVE-2026-98088 records a Unknown severity vulnerability in scsi: mpt3sas: Avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=728bbc6cbff70051813730fb7977f5d99d867e12 <0a5f7cdb0cb911584720591069065f09c59ec4fc || >=728bbc6cbff70051813730fb7977f5d99d867e12 <7b23144c3ff6e46d7d4a464b02f8944265684e39 || >=728bbc6cbff70051813730fb7977f5d99d867e12 <45504e621b7e884abe59f201e093a3eac7fca7fe || >=728bbc6cbff70051813730fb7977f5d99d867e12 <e0d26fe176a8db6ccad4ab38c5bab29391c1946b | 0a5f7cdb0cb911584720591069065f09c59ec4fc, 7b23144c3ff6e46d7d4a464b02f8944265684e39, 45504e621b7e884abe59f201e093a3eac7fca7fe, e0d26fe176a8db6ccad4ab38c5bab29391c1946b |
| Linux/Linuxgeneric | 5.3 | Not reported |
Published upstream
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 25, 2026
In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues() dev_to_node() can return NUMA_NO_NODE (-1) on systems without NUMA topology information for the PCI device, such as single-socket boards that don't expose device-to-node affinity. Passing -1 directly into cpumask_of_node() indexes node_to_cpumask_map[-1], an out-of-bounds array read caught by UBSAN: UBSAN: array-index-out-of-bounds in arch/x86/include/asm/topology.h:72:28 index -1 is out of range for type 'cpumask *[1024]' Fall back to cpu_online_mask when no NUMA node is available, rather than assuming dev_to_node() always returns a valid node index.
Quoted source text, attributed separately from HOL analysis.