« Volver al listado

CVE-2026-90186

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

null_blk: reject per-device queue resize for shared tag set

When shared_tags is enabled, null_setup_tagset() makes the device use the global tag_set, whose driver_data stays NULL. null_map_queues() therefore falls back to the module-wide g_submit_queues/g_poll_queues instead of any per-device value.

Resizing submit_queues or poll_queues via configfs on such a device calls blk_mq_update_nr_hw_queues() on the shared set, shrinking set->nr_hw_queues. __blk_mq_realloc_hw_ctxs() only grows the q->queue_hw_ctx[] allocation, so on shrink it merely exits and NULLs the now-excess hctx slots. null_map_queues(), however, keeps mapping CPUs with the unchanged g_submit_queues/g_poll_queues, so mq_map[] ends up pointing at those NULLed hctx slots. blk_mq_map_swqueue() then dereferences the NULL hctx (hctx->cpumask), crashing the kernel:

Leer descripción completaMostrar menos

Reproducer: modprobe null_blk shared_tags=1 submit_queues=64 poll_queues=1 mkdir /sys/kernel/config/nullb/dev echo 1 > /sys/kernel/config/nullb/dev/power echo 1 > /sys/kernel/config/nullb/dev/submit_queues

A per-device resize of a shared tag set is meaningless anyway, so reject it with -EINVAL in nullb_update_nr_hw_queues() when the device is bound to the global tag_set.

Detalles técnicos trazas, registros y código del informe original
[  460.218374] KASAN: null-ptr-deref in range [0x0000000000000098-0x000000000000009f]
[  460.219003] CPU: 24 UID: 0 PID: 1492 Comm: sh Not tainted 7.2.0-rc2+ #67 PREEMPT(full)
[  460.219792] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-4.fc41 04/01/2014
[  460.220452] RIP: 0010:blk_mq_map_swqueue+0x4db/0x1430
......
[  460.228977] Call Trace:
[  460.229175]  <TASK>
[  460.229354]  blk_mq_update_nr_hw_queues+0xd49/0x11c0
[  460.229779]  ? __pfx_blk_mq_update_nr_hw_queues+0x10/0x10
[  460.230200]  nullb_update_nr_hw_queues+0x1a9/0x370 [null_blk]
[  460.230694]  nullb_device_submit_queues_store+0xd9/0x170 [null_blk]
[  460.231190]  ? __pfx_nullb_device_submit_queues_store+0x10/0x10 [null_blk]
[  460.231776]  ? configfs_write_iter+0x35c/0x4e0
[  460.232122]  configfs_write_iter+0x286/0x4e0
[  460.232460]  vfs_write+0x52d/0xd00
[  460.232779]  ? __x64_sys_openat+0x108/0x1d0
[  460.233106]  ? __pfx_vfs_write+0x10/0x10
[  460.233413]  ? fdget_pos+0x1cf/0x4c0
[  460.233745]  ? fput_close+0x133/0x190
[  460.234038]  ? __pfx_expand_files+0x10/0x10
[  460.234368]  ksys_write+0xfc/0x1d0

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90186",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "45919fbfe1c487c17ea1d198534339a5e8abeae3",
              "lessThan": "9c7bae099ddc92676ad1b7e29dd6c089e5f6196c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "45919fbfe1c487c17ea1d198534339a5e8abeae3",
              "lessThan": "fcd53f3e8b758c79c3f2420d28a2a1dce6fda61a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "45919fbfe1c487c17ea1d198534339a5e8abeae3",
              "lessThan": "f609f7bf9ce8c2fc427705c4a9f623a281239d06",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "45919fbfe1c487c17ea1d198534339a5e8abeae3",
              "lessThan": "3e35ad503386a2e8a0e0460530dcbf421c79f6f2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "45919fbfe1c487c17ea1d198534339a5e8abeae3",
              "lessThan": "baff300541a0012907cdde349728739fe16176d7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "45919fbfe1c487c17ea1d198534339a5e8abeae3",
              "lessThan": "1cdfe2fa62b48728a9b436fbbd3dbe4c11593e24",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/block/null_blk/main.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.5"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.5",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/block/null_blk/main.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:13.127",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/1cdfe2fa62b48728a9b436fbbd3dbe4c11593e24",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3e35ad503386a2e8a0e0460530dcbf421c79f6f2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9c7bae099ddc92676ad1b7e29dd6c089e5f6196c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/baff300541a0012907cdde349728739fe16176d7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f609f7bf9ce8c2fc427705c4a9f623a281239d06",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fcd53f3e8b758c79c3f2420d28a2a1dce6fda61a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnull_blk: reject per-device queue resize for shared tag set\n\nWhen shared_tags is enabled, null_setup_tagset() makes the device use the\nglobal tag_set, whose driver_data stays NULL. null_map_queues() therefore\nfalls back to the module-wide g_submit_queues/g_poll_queues instead of any\nper-device value.\n\nResizing submit_queues or poll_queues via configfs on such a device calls\nblk_mq_update_nr_hw_queues() on the shared set, shrinking\nset->nr_hw_queues.  __blk_mq_realloc_hw_ctxs() only grows the\nq->queue_hw_ctx[] allocation, so on shrink it merely exits and NULLs the\nnow-excess hctx slots. null_map_queues(), however, keeps mapping CPUs with\nthe unchanged g_submit_queues/g_poll_queues, so mq_map[] ends up pointing\nat those NULLed hctx slots. blk_mq_map_swqueue() then dereferences the NULL\nhctx (hctx->cpumask), crashing the kernel:\n\n[  460.218374] KASAN: null-ptr-deref in range [0x0000000000000098-0x000000000000009f]\n[  460.219003] CPU: 24 UID: 0 PID: 1492 Comm: sh Not tainted 7.2.0-rc2+ #67 PREEMPT(full)\n[  460.219792] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-4.fc41 04/01/2014\n[  460.220452] RIP: 0010:blk_mq_map_swqueue+0x4db/0x1430\n......\n[  460.228977] Call Trace:\n[  460.229175]  <TASK>\n[  460.229354]  blk_mq_update_nr_hw_queues+0xd49/0x11c0\n[  460.229779]  ? __pfx_blk_mq_update_nr_hw_queues+0x10/0x10\n[  460.230200]  nullb_update_nr_hw_queues+0x1a9/0x370 [null_blk]\n[  460.230694]  nullb_device_submit_queues_store+0xd9/0x170 [null_blk]\n[  460.231190]  ? __pfx_nullb_device_submit_queues_store+0x10/0x10 [null_blk]\n[  460.231776]  ? configfs_write_iter+0x35c/0x4e0\n[  460.232122]  configfs_write_iter+0x286/0x4e0\n[  460.232460]  vfs_write+0x52d/0xd00\n[  460.232779]  ? __x64_sys_openat+0x108/0x1d0\n[  460.233106]  ? __pfx_vfs_write+0x10/0x10\n[  460.233413]  ? fdget_pos+0x1cf/0x4c0\n[  460.233745]  ? fput_close+0x133/0x190\n[  460.234038]  ? __pfx_expand_files+0x10/0x10\n[  460.234368]  ksys_write+0xfc/0x1d0\n\nReproducer:\nmodprobe null_blk shared_tags=1 submit_queues=64 poll_queues=1\nmkdir /sys/kernel/config/nullb/dev\necho 1 > /sys/kernel/config/nullb/dev/power\necho 1 > /sys/kernel/config/nullb/dev/submit_queues\n\nA per-device resize of a shared tag set is meaningless anyway, so reject it\nwith -EINVAL in nullb_update_nr_hw_queues() when the device is bound to the\nglobal tag_set."
    }
  ],
  "lastModified": "2026-09-17T17:17:13.127",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}