CVE-2026-72088

Source
https://cve.org/CVERecord?id=CVE-2026-72088
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72088.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72088
Downstream
Published
2026-08-15T05:52:36.155Z
Modified
2026-08-18T03:31:23.334331751Z
Summary
scsi: hpsa: Fix DMA mapping leak on IOACCEL2 reset path
Details

In the Linux kernel, the following vulnerability has been resolved:

scsi: hpsa: Fix DMA mapping leak on IOACCEL2 reset path

If physdisk->inreset is set, the function returns directly without undoing the resources acquired for the command. Add the missing error cleanup by unmapping the IOACCEL2 SG chain block when needed, unmapping the SCSI command, and dropping the outstanding IOACCEL command count before returning.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72088.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c5dfd106414f3e038fee5c6f0800fd55ed07b41d
Fixed
fca5edd748f00e87f2dd55a6333722b46af30e74
Fixed
fb40928c59329a50eadb3ce8bfd7a67f490a6212
Fixed
018cbce6ee158244bb76cf638e8e3054e240aea9
Fixed
a61de4d7e22a9ab9a90094d0e180b378e09a1d2c
Fixed
e7bde072cceefc564413b46d64017c47a2e9977d
Fixed
d495b403d5b357dfe506b963bd7a78ecd5c7b667
Fixed
782e1bf48672be44265c48e14602696c3c8ed904
Fixed
e166bafc483e927150cb9b5f286c9191ea0df84e

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72088.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.3.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72088.json"