CVE-2026-90190
In the Linux kernel, the following vulnerability has been resolved:
null_blk: use DEFINE_MUTEX for the file-scope mutex
In null_init(), mutex_init(&lock) currently happens after configfs_register_subsystem(), which exposes the nullb subsystem to userspace. A racing mkdir() into /sys/kernel/config/nullb/ can reach null_find_dev_by_name() -> mutex_lock(&lock) before the mutex is initialized, trigger warning:
Replace the runtime mutex_init(&lock) with a static DEFINE_MUTEX(lock) declaration to fix this issue.
Detalles técnicos trazas, registros y código del informe original
[ 123.137788] DEBUG_LOCKS_WARN_ON(lock->magic != lock) [ 123.137796] WARNING: kernel/locking/mutex.c:159 at mutex_lock+0x171/0x1c0, CPU#13: mkdir/1301 [ 123.140090] Modules linked in: null_blk(+) nft_fib_inet nft_fib_ipv4 ...... [ 123.154926] Call Trace: [ 123.155172] <TASK> [ 123.155419] ? __pfx_mutex_lock+0x10/0x10 [ 123.156181] ? __pfx__raw_spin_lock+0x10/0x10 [ 123.156571] nullb_group_make_group+0x20/0x100 [null_blk] [ 123.157011] configfs_mkdir+0x47b/0xc70 [ 123.157337] ? __pfx_configfs_mkdir+0x10/0x10 [ 123.157719] ? may_create_dentry+0x242/0x2e0 [ 123.158061] vfs_mkdir+0x2a9/0x6c0 [ 123.158352] filename_mkdirat+0x3dc/0x500 [ 123.158710] ? __pfx_filename_mkdirat+0x10/0x10 [ 123.159070] ? strncpy_from_user+0x3a/0x1d0 [ 123.159413] __x64_sys_mkdir+0x6b/0x90 [ 123.159760] do_syscall_64+0xea/0x600
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/017dac7670909eaea3eb36e6b3b5a8be9ce0a14d
- https://git.kernel.org/stable/c/0a8c2f7b95981913ac370683e34db4906970c210
- https://git.kernel.org/stable/c/234117949da3b3f9705a21b66094f9f30bbe681d
- https://git.kernel.org/stable/c/349903f7ee72f7ac5b7a98840d701b2082d140a3
- https://git.kernel.org/stable/c/c7dea90c9b4ef1dfbd2e4df36de180c76fd7c33c
- https://git.kernel.org/stable/c/f9f4ca45c770b7eec83fea6c9b727b26e691b513
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-90190",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "49c3b9266a718dbd73c42e004288b4bb2ea0ac0b",
"lessThan": "f9f4ca45c770b7eec83fea6c9b727b26e691b513",
"versionType": "git"
},
{
"status": "affected",
"version": "49c3b9266a718dbd73c42e004288b4bb2ea0ac0b",
"lessThan": "349903f7ee72f7ac5b7a98840d701b2082d140a3",
"versionType": "git"
},
{
"status": "affected",
"version": "49c3b9266a718dbd73c42e004288b4bb2ea0ac0b",
"lessThan": "0a8c2f7b95981913ac370683e34db4906970c210",
"versionType": "git"
},
{
"status": "affected",
"version": "49c3b9266a718dbd73c42e004288b4bb2ea0ac0b",
"lessThan": "c7dea90c9b4ef1dfbd2e4df36de180c76fd7c33c",
"versionType": "git"
},
{
"status": "affected",
"version": "49c3b9266a718dbd73c42e004288b4bb2ea0ac0b",
"lessThan": "234117949da3b3f9705a21b66094f9f30bbe681d",
"versionType": "git"
},
{
"status": "affected",
"version": "49c3b9266a718dbd73c42e004288b4bb2ea0ac0b",
"lessThan": "017dac7670909eaea3eb36e6b3b5a8be9ce0a14d",
"versionType": "git"
}
],
"programFiles": [
"drivers/block/null_blk/main.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.19"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.19",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.1.188",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.157",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.110",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.52",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/block/null_blk/main.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-17T17:17:13.670",
"references": [
{
"url": "https://git.kernel.org/stable/c/017dac7670909eaea3eb36e6b3b5a8be9ce0a14d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/0a8c2f7b95981913ac370683e34db4906970c210",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/234117949da3b3f9705a21b66094f9f30bbe681d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/349903f7ee72f7ac5b7a98840d701b2082d140a3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c7dea90c9b4ef1dfbd2e4df36de180c76fd7c33c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f9f4ca45c770b7eec83fea6c9b727b26e691b513",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnull_blk: use DEFINE_MUTEX for the file-scope mutex\n\nIn null_init(), mutex_init(&lock) currently happens after\nconfigfs_register_subsystem(), which exposes the nullb subsystem to\nuserspace. A racing mkdir() into /sys/kernel/config/nullb/ can reach\nnull_find_dev_by_name() -> mutex_lock(&lock) before the mutex is\ninitialized, trigger warning:\n\n[ 123.137788] DEBUG_LOCKS_WARN_ON(lock->magic != lock)\n[ 123.137796] WARNING: kernel/locking/mutex.c:159 at mutex_lock+0x171/0x1c0, CPU#13: mkdir/1301\n[ 123.140090] Modules linked in: null_blk(+) nft_fib_inet nft_fib_ipv4\n......\n[ 123.154926] Call Trace:\n[ 123.155172] <TASK>\n[ 123.155419] ? __pfx_mutex_lock+0x10/0x10\n[ 123.156181] ? __pfx__raw_spin_lock+0x10/0x10\n[ 123.156571] nullb_group_make_group+0x20/0x100 [null_blk]\n[ 123.157011] configfs_mkdir+0x47b/0xc70\n[ 123.157337] ? __pfx_configfs_mkdir+0x10/0x10\n[ 123.157719] ? may_create_dentry+0x242/0x2e0\n[ 123.158061] vfs_mkdir+0x2a9/0x6c0\n[ 123.158352] filename_mkdirat+0x3dc/0x500\n[ 123.158710] ? __pfx_filename_mkdirat+0x10/0x10\n[ 123.159070] ? strncpy_from_user+0x3a/0x1d0\n[ 123.159413] __x64_sys_mkdir+0x6b/0x90\n[ 123.159760] do_syscall_64+0xea/0x600\n\nReplace the runtime mutex_init(&lock) with a static DEFINE_MUTEX(lock)\ndeclaration to fix this issue."
}
],
"lastModified": "2026-09-17T17:17:13.670",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}