« Volver al listado

CVE-2026-90184

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

null_blk: serialize configfs attribute updates with device setup

The attribute store methods generated with NULLB_DEVICE_ATTR() refuse to change the configuration of a live device by testing NULLB_DEV_FL_CONFIGURED, but that flag is only set by nullb_device_power_store() after null_add_dev() has returned, and the store methods take no lock at all. configfs only serializes writes to the same open file (buffer->mutex), so a write to any attribute can run concurrently with null_add_dev() and change the device configuration while it is being used.

Leer descripción completaMostrar menos

null_add_dev() reads the configuration several times, e.g. dev->zoned is read once to set up the queue limits and once to initialize the zone resources:

blk_revalidate_disk_zones() is then called for a queue that does not have BLK_FEAT_ZONED set, which triggers its WARN_ON_ONCE() and fails the device setup with -EIO:

Clearing dev->zoned in the same window is worse: the queue is created with BLK_FEAT_ZONED but the zone resources are never initialized, so add_disk() succeeds for a zoned disk that has no zones. And a store that lands after the last dev->zoned test leaves dev->zoned set while dev->zones is still NULL, which null_process_zoned_cmd() dereferences on the first write.

Fix this by taking the global lock, which nullb_device_power_store() already holds across null_add_dev() and null_del_dev(), around both the NULLB_DEV_FL_CONFIGURED test and the update of the device configuration. The submit_queues and poll_queues apply callbacks are now called with that lock held, so remove the locking they did themselves.

Since the store methods can run as soon as configfs_register_subsystem() returns, that is, before null_init() gets to mutex_init(&lock), also initialize the lock statically with DEFINE_MUTEX().

Detalles técnicos trazas, registros y código del informe original
  CPU0: echo 1 > nullb0/power         CPU1: echo 1 > nullb0/zoned
  nullb_device_power_store()
    mutex_lock(&lock)
    null_add_dev()
      if (dev->zoned) -> false
        /* no BLK_FEAT_ZONED */       nullb_device_zoned_store()
                                        test_bit(FL_CONFIGURED) -> 0
                                        dev->zoned = true
      blk_mq_alloc_disk()
        /* queue is not zoned */
      if (nullb->dev->zoned) -> true
        null_register_zoned_dev()
          blk_revalidate_disk_zones()

  WARNING: CPU: 2 PID: 322 at block/blk-zoned.c:2357 blk_revalidate_disk_zones+0x4c/0x560

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90184",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3bf2bd20734e3e6ffda53719a9c10fb3ee9c5ffa",
              "lessThan": "6352e7ead2d8111802a554eeb94886f5a9894bb9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3bf2bd20734e3e6ffda53719a9c10fb3ee9c5ffa",
              "lessThan": "7de792b4c48fba02a36a8077032f7d5093c925e5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3bf2bd20734e3e6ffda53719a9c10fb3ee9c5ffa",
              "lessThan": "aed8af338a09a64d63b068a803c4ecfc5701dd4c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3bf2bd20734e3e6ffda53719a9c10fb3ee9c5ffa",
              "lessThan": "32456a85995579e56c60cc53c357cda75a9d4f7c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3bf2bd20734e3e6ffda53719a9c10fb3ee9c5ffa",
              "lessThan": "d3d35dd045a35991bf6fd13de5f293e6dd7bf3b3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3bf2bd20734e3e6ffda53719a9c10fb3ee9c5ffa",
              "lessThan": "4e1f23f9c33c156be7e313b40695af5a3a834739",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/block/null_blk/main.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.14"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.14",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/block/null_blk/main.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:12.833",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/32456a85995579e56c60cc53c357cda75a9d4f7c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4e1f23f9c33c156be7e313b40695af5a3a834739",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6352e7ead2d8111802a554eeb94886f5a9894bb9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7de792b4c48fba02a36a8077032f7d5093c925e5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/aed8af338a09a64d63b068a803c4ecfc5701dd4c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d3d35dd045a35991bf6fd13de5f293e6dd7bf3b3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnull_blk: serialize configfs attribute updates with device setup\n\nThe attribute store methods generated with NULLB_DEVICE_ATTR() refuse to\nchange the configuration of a live device by testing\nNULLB_DEV_FL_CONFIGURED, but that flag is only set by\nnullb_device_power_store() after null_add_dev() has returned, and the\nstore methods take no lock at all. configfs only serializes writes to\nthe same open file (buffer->mutex), so a write to any attribute can run\nconcurrently with null_add_dev() and change the device configuration\nwhile it is being used.\n\nnull_add_dev() reads the configuration several times, e.g. dev->zoned is\nread once to set up the queue limits and once to initialize the zone\nresources:\n\n  CPU0: echo 1 > nullb0/power         CPU1: echo 1 > nullb0/zoned\n  nullb_device_power_store()\n    mutex_lock(&lock)\n    null_add_dev()\n      if (dev->zoned) -> false\n        /* no BLK_FEAT_ZONED */       nullb_device_zoned_store()\n                                        test_bit(FL_CONFIGURED) -> 0\n                                        dev->zoned = true\n      blk_mq_alloc_disk()\n        /* queue is not zoned */\n      if (nullb->dev->zoned) -> true\n        null_register_zoned_dev()\n          blk_revalidate_disk_zones()\n\nblk_revalidate_disk_zones() is then called for a queue that does not\nhave BLK_FEAT_ZONED set, which triggers its WARN_ON_ONCE() and fails the\ndevice setup with -EIO:\n\n  WARNING: CPU: 2 PID: 322 at block/blk-zoned.c:2357 blk_revalidate_disk_zones+0x4c/0x560\n\nClearing dev->zoned in the same window is worse: the queue is created\nwith BLK_FEAT_ZONED but the zone resources are never initialized, so\nadd_disk() succeeds for a zoned disk that has no zones. And a store that\nlands after the last dev->zoned test leaves dev->zoned set while\ndev->zones is still NULL, which null_process_zoned_cmd() dereferences on\nthe first write.\n\nFix this by taking the global lock, which nullb_device_power_store()\nalready holds across null_add_dev() and null_del_dev(), around both the\nNULLB_DEV_FL_CONFIGURED test and the update of the device configuration.\nThe submit_queues and poll_queues apply callbacks are now called with\nthat lock held, so remove the locking they did themselves.\n\nSince the store methods can run as soon as configfs_register_subsystem()\nreturns, that is, before null_init() gets to mutex_init(&lock), also\ninitialize the lock statically with DEFINE_MUTEX()."
    }
  ],
  "lastModified": "2026-09-17T17:17:12.833",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}