CVE-2026-43473: scsi: mpi3mr: Add NULL checks when resetting request and reply queues

Published May 8, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

scsi: mpi3mr: Add NULL checks when resetting request and reply queues

The driver encountered a crash during resource cleanup when the reply and request queues were NULL due to freed memory. This issue occurred when the creation of reply or request queues failed, and the driver freed the memory first, but attempted to mem set the content of the freed memory, leading to a system crash.

Add NULL pointer checks for reply and request queues before accessing the reply/request memory during cleanup

Affected Software

7 affected components
Linux Linux kernel (scsi: mpi3mr driver)
Linux Linux kernel>=5.17<6.1.167
Linux Linux kernel>=6.2<6.6.130
Linux Linux kernel>=6.7<6.12.78
Linux Linux kernel>=6.13<6.18.19
Linux Linux kernel>=6.19<6.19.9
Linux Linux kernel=7.0-rc1

Event History

May 8, 2026
CVE Published
via MITRE·02:22 PM
Data Sourced
via MITRE·02:22 PM
Description
Data Sourced
via NVD·03:17 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-43473?

CVE-2026-43473 has been rated as a medium severity vulnerability.

2

How do I fix CVE-2026-43473?

To resolve CVE-2026-43473, update the Linux kernel to the latest version that includes the patch for the mpi3mr driver.

3

What products are affected by CVE-2026-43473?

CVE-2026-43473 affects the Linux kernel specifically in the mpi3mr driver.

4

What is the impact of CVE-2026-43473?

The impact of CVE-2026-43473 includes potential crashes during resource cleanup in the affected driver.

5

When was CVE-2026-43473 reported?

CVE-2026-43473 was reported and resolved in 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203