CVE-2026-72081

high

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: elx: efct: Fix I/O leak on unsupported additional CDB efct_dispatch_fcp_cmd() allocates an efct_io before dispatching an unsolicited FCP command. If the command has an unsupported additional CDB, the function returns -EIO before handing the IO to the SCSI layer. Free the allocated IO before returning from this error path.

References

https://git.kernel.org/stable/c/df87532e9212238509f23effd0ca39d9c3062d21

https://git.kernel.org/stable/c/9d479f50a6067954259414aa66d816c7df081286

https://git.kernel.org/stable/c/9cb2d5291dbfe7bed565ead3337047dee9ed1064

https://git.kernel.org/stable/c/94cbfed191248dc88c23fc881119bb399486ddfd

https://git.kernel.org/stable/c/8c689a8f229223cec4a821c65cfe40f8e8c56470

https://git.kernel.org/stable/c/42a391d508e1f52fda5d81344e100a53c00898e3

https://git.kernel.org/stable/c/235159f75ab6f95484494db4cc031663e5ee4680

Details

Source: Mitre, NVD

Published: 2026-08-15

Updated: 2026-08-17

Risk Information

CVSS v2

Base Score: 5.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 7.1

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Severity: High

EPSS

EPSS: 0.00215