CVE-2026-72081
N/AIn the Linux kernel, the following vulnerability has been resolved: scsi: elx: efct: Fix I/O leak on unsupported additional CDB efct_dispatch_fcp_cmd() allocates an efct_io before dispatching an unsolicited FCP command. If the command has an unsupported additional CDB, the function returns -EIO before handing the IO to the SCSI layer. Free the allocated IO before returning from this error path.
NO EXPLOITATION SIGNALS
No known exploitation, public exploit, or elevated probability at this time. Track for changes.
Exploitation likelihood
0.2%chance of exploitation in 30 days · 12th percentile
○ In CISA KEV
○ Public exploit / PoC
Impact if exploited
—CVSS · not scored
- No impact metrics
Proof of concept & exploit code
- github-search Search GitHub for public PoC repos
Test against your own equipment
curl -s https://vulnpedia.com/cve/CVE-2026-72081/poc.jsonMachine-readable PoC index for this CVE (for automation).Listed for defensive triage, patch verification, and authorized testing on systems you own. Machine-readable: /cve/CVE-2026-72081/poc.json
References
Technical & other
- https://git.kernel.org/stable/c/42a391d508e1f52fda5d81344e100a53c00898e3
- https://git.kernel.org/stable/c/9d479f50a6067954259414aa66d816c7df081286
- https://git.kernel.org/stable/c/8c689a8f229223cec4a821c65cfe40f8e8c56470
- https://git.kernel.org/stable/c/235159f75ab6f95484494db4cc031663e5ee4680
- https://git.kernel.org/stable/c/df87532e9212238509f23effd0ca39d9c3062d21
- https://git.kernel.org/stable/c/94cbfed191248dc88c23fc881119bb399486ddfd
- https://git.kernel.org/stable/c/9cb2d5291dbfe7bed565ead3337047dee9ed1064