In the Linux kernel, the following vulnerability has been resolved:
scsi: lpfc: Fix memory leak in lpfc_create_port()
Commit 5e633302ace1 ("scsi: lpfc: vmid: Add support for VMID in mailbox command") introduced allocations for the VMID resources in lpfc_create_port() after the call to scsi_host_alloc(). Upon failure on the VMID allocations, the new code would branch to the 'out' label, which returns NULL without unwinding anything, thus skipping the call to scsi_host_put().
Fix the problem by creating a separate label 'out_free_vmid' to unwind the VMID resources and make the 'out_put_shost' label call only scsi_host_put(), as was done before the introduction of allocations for VMID.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Dec 31, 2025 | Dec 31, 2025 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Dec 30, 2025 |
| Ubuntu | — | Upgrade linux-kvmUpgrade linux-azure-5.15Upgrade linux-oracleUpgrade linux-gkeopUpgrade linux-intel-iotgUpgrade linux-gcpUpgrade linux-nvidiaUpgrade linux-intel-iotg-5.15Upgrade linuxUpgrade linux-ibmUpgrade linux-oracle-5.15Upgrade linux-gcp-5.15Upgrade linux-bluefieldUpgrade linux-realtimeUpgrade linux-lowlatencyUpgrade linux-riscv-5.15Upgrade linux-aws-5.15Upgrade linux-raspiUpgrade linux-azure-fdeUpgrade linux-gkeUpgrade linux-awsUpgrade linux-lowlatency-hwe-5.15Upgrade linux-azureUpgrade linux-hwe-5.15 | Jan 6, 2026 | Jan 2, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub