« Volver al listado

CVE-2026-90190

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

null_blk: use DEFINE_MUTEX for the file-scope mutex

In null_init(), mutex_init(&lock) currently happens after configfs_register_subsystem(), which exposes the nullb subsystem to userspace. A racing mkdir() into /sys/kernel/config/nullb/ can reach null_find_dev_by_name() -> mutex_lock(&lock) before the mutex is initialized, trigger warning:

Replace the runtime mutex_init(&lock) with a static DEFINE_MUTEX(lock) declaration to fix this issue.

Detalles técnicos trazas, registros y código del informe original
[  123.137788] DEBUG_LOCKS_WARN_ON(lock->magic != lock)
[  123.137796] WARNING: kernel/locking/mutex.c:159 at mutex_lock+0x171/0x1c0, CPU#13: mkdir/1301
[  123.140090] Modules linked in: null_blk(+) nft_fib_inet nft_fib_ipv4
......
[  123.154926] Call Trace:
[  123.155172]  <TASK>
[  123.155419]  ? __pfx_mutex_lock+0x10/0x10
[  123.156181]  ? __pfx__raw_spin_lock+0x10/0x10
[  123.156571]  nullb_group_make_group+0x20/0x100 [null_blk]
[  123.157011]  configfs_mkdir+0x47b/0xc70
[  123.157337]  ? __pfx_configfs_mkdir+0x10/0x10
[  123.157719]  ? may_create_dentry+0x242/0x2e0
[  123.158061]  vfs_mkdir+0x2a9/0x6c0
[  123.158352]  filename_mkdirat+0x3dc/0x500
[  123.158710]  ? __pfx_filename_mkdirat+0x10/0x10
[  123.159070]  ? strncpy_from_user+0x3a/0x1d0
[  123.159413]  __x64_sys_mkdir+0x6b/0x90
[  123.159760]  do_syscall_64+0xea/0x600

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90190",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "49c3b9266a718dbd73c42e004288b4bb2ea0ac0b",
              "lessThan": "f9f4ca45c770b7eec83fea6c9b727b26e691b513",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "49c3b9266a718dbd73c42e004288b4bb2ea0ac0b",
              "lessThan": "349903f7ee72f7ac5b7a98840d701b2082d140a3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "49c3b9266a718dbd73c42e004288b4bb2ea0ac0b",
              "lessThan": "0a8c2f7b95981913ac370683e34db4906970c210",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "49c3b9266a718dbd73c42e004288b4bb2ea0ac0b",
              "lessThan": "c7dea90c9b4ef1dfbd2e4df36de180c76fd7c33c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "49c3b9266a718dbd73c42e004288b4bb2ea0ac0b",
              "lessThan": "234117949da3b3f9705a21b66094f9f30bbe681d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "49c3b9266a718dbd73c42e004288b4bb2ea0ac0b",
              "lessThan": "017dac7670909eaea3eb36e6b3b5a8be9ce0a14d",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/block/null_blk/main.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.19"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.19",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/block/null_blk/main.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:13.670",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/017dac7670909eaea3eb36e6b3b5a8be9ce0a14d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/0a8c2f7b95981913ac370683e34db4906970c210",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/234117949da3b3f9705a21b66094f9f30bbe681d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/349903f7ee72f7ac5b7a98840d701b2082d140a3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c7dea90c9b4ef1dfbd2e4df36de180c76fd7c33c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f9f4ca45c770b7eec83fea6c9b727b26e691b513",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnull_blk: use DEFINE_MUTEX for the file-scope mutex\n\nIn null_init(), mutex_init(&lock) currently happens after\nconfigfs_register_subsystem(), which exposes the nullb subsystem to\nuserspace. A racing mkdir() into /sys/kernel/config/nullb/ can reach\nnull_find_dev_by_name() -> mutex_lock(&lock) before the mutex is\ninitialized, trigger warning:\n\n[  123.137788] DEBUG_LOCKS_WARN_ON(lock->magic != lock)\n[  123.137796] WARNING: kernel/locking/mutex.c:159 at mutex_lock+0x171/0x1c0, CPU#13: mkdir/1301\n[  123.140090] Modules linked in: null_blk(+) nft_fib_inet nft_fib_ipv4\n......\n[  123.154926] Call Trace:\n[  123.155172]  <TASK>\n[  123.155419]  ? __pfx_mutex_lock+0x10/0x10\n[  123.156181]  ? __pfx__raw_spin_lock+0x10/0x10\n[  123.156571]  nullb_group_make_group+0x20/0x100 [null_blk]\n[  123.157011]  configfs_mkdir+0x47b/0xc70\n[  123.157337]  ? __pfx_configfs_mkdir+0x10/0x10\n[  123.157719]  ? may_create_dentry+0x242/0x2e0\n[  123.158061]  vfs_mkdir+0x2a9/0x6c0\n[  123.158352]  filename_mkdirat+0x3dc/0x500\n[  123.158710]  ? __pfx_filename_mkdirat+0x10/0x10\n[  123.159070]  ? strncpy_from_user+0x3a/0x1d0\n[  123.159413]  __x64_sys_mkdir+0x6b/0x90\n[  123.159760]  do_syscall_64+0xea/0x600\n\nReplace the runtime mutex_init(&lock) with a static DEFINE_MUTEX(lock)\ndeclaration to fix this issue."
    }
  ],
  "lastModified": "2026-09-17T17:17:13.670",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}