{"id":"CVE-2026-72081","summary":"scsi: elx: efct: Fix I/O leak on unsupported additional CDB","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: elx: efct: Fix I/O leak on unsupported additional CDB\n\nefct_dispatch_fcp_cmd() allocates an efct_io before dispatching an\nunsolicited FCP command. If the command has an unsupported additional\nCDB, the function returns -EIO before handing the IO to the SCSI layer.\n\nFree the allocated IO before returning from this error path.","modified":"2026-08-18T03:31:15.423402110Z","published":"2026-08-15T05:52:30.545Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72081.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/235159f75ab6f95484494db4cc031663e5ee4680"},{"type":"WEB","url":"https://git.kernel.org/stable/c/42a391d508e1f52fda5d81344e100a53c00898e3"},{"type":"WEB","url":"https://git.kernel.org/stable/c/8c689a8f229223cec4a821c65cfe40f8e8c56470"},{"type":"WEB","url":"https://git.kernel.org/stable/c/94cbfed191248dc88c23fc881119bb399486ddfd"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9cb2d5291dbfe7bed565ead3337047dee9ed1064"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9d479f50a6067954259414aa66d816c7df081286"},{"type":"WEB","url":"https://git.kernel.org/stable/c/df87532e9212238509f23effd0ca39d9c3062d21"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72081.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72081"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"f45ae6aac0a077ca15a6e7baae0a62eef099ea7d"},{"fixed":"42a391d508e1f52fda5d81344e100a53c00898e3"},{"fixed":"9d479f50a6067954259414aa66d816c7df081286"},{"fixed":"8c689a8f229223cec4a821c65cfe40f8e8c56470"},{"fixed":"235159f75ab6f95484494db4cc031663e5ee4680"},{"fixed":"df87532e9212238509f23effd0ca39d9c3062d21"},{"fixed":"94cbfed191248dc88c23fc881119bb399486ddfd"},{"fixed":"9cb2d5291dbfe7bed565ead3337047dee9ed1064"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72081.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.14.0"},{"fixed":"5.15.212"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.178"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.145"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.97"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.40"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.5"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72081.json"}}],"schema_version":"1.9.0"}