---
id: CVE-2026-98088
title: >-
  In the Linux kernel, the following vulnerability has been resolved:


  scsi: mpt3sas: Avoid out-of-bounds cpumask_of_node() call in
  _base_assign_reply_queues()


  dev_to_node() can return NUMA_NO_NODE (-1) on systems without NUMA

  topology in…
summary: >-
  In the Linux kernel, the following vulnerability has been resolved:


  scsi: mpt3sas: Avoid out-of-bounds cpumask_of_node() call in
  _base_assign_reply_queues()


  dev_to_node() can return NUMA_NO_NODE (-1) on systems without NUMA

  topology in…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 728bbc6cbff70051813730fb7977f5d99d867e12 <
    0a5f7cdb0cb911584720591069065f09c59ec4fc
  - >-
    Linux >= 728bbc6cbff70051813730fb7977f5d99d867e12 <
    7b23144c3ff6e46d7d4a464b02f8944265684e39
  - >-
    Linux >= 728bbc6cbff70051813730fb7977f5d99d867e12 <
    45504e621b7e884abe59f201e093a3eac7fca7fe
  - >-
    Linux >= 728bbc6cbff70051813730fb7977f5d99d867e12 <
    e0d26fe176a8db6ccad4ab38c5bab29391c1946b
  - Linux 5.3
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T11:17:38.480'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98088'
references:
  - url: 'https://git.kernel.org/stable/c/0a5f7cdb0cb911584720591069065f09c59ec4fc'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/45504e621b7e884abe59f201e093a3eac7fca7fe'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/7b23144c3ff6e46d7d4a464b02f8944265684e39'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e0d26fe176a8db6ccad4ab38c5bab29391c1946b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-25T11:06:38.833Z'
epss: 0.00168
epssPercentile: 0.05408
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

scsi: mpt3sas: Avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues()

dev_to_node() can return NUMA_NO_NODE (-1) on systems without NUMA
topology information for the PCI device, such as single-socket boards
that don't expose device-to-node affinity. Passing -1 directly into
cpumask_of_node() indexes node_to_cpumask_map[-1], an out-of-bounds
array read caught by UBSAN:

  UBSAN: array-index-out-of-bounds in arch/x86/include/asm/topology.h:72:28
  index -1 is out of range for type 'cpumask *[1024]'

Fall back to cpu_online_mask when no NUMA node is available, rather than
assuming dev_to_node() always returns a valid node index.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
