« Volver al listado

CVE-2026-90187

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

null_blk: free zones array on device power-off

null_init_zoned_dev() allocates dev->zones when a zoned device is powered on, but null_del_dev() never frees it on power-off; dev->zones is only freed later in null_free_dev(), when the configfs directory is removed. If the device is powered off and then on again, null_init_zoned_dev() allocates a new array and overwrites the dev->zones pointer, leaking the previous allocation each power cycle.

Free dev->zones in null_del_dev() via null_free_zoned_dev() to solve it. And calling null_free_zoned_dev() in null_free_dev() is no longer necessary because every caller already invokes null_del_dev() first: via nullb_group_drop_item() before nullb_device_release(), in the null_add_dev() error path of null_create_dev(), and in null_destroy_dev(). Remove the redundant call.

Leer descripción completaMostrar menos

And take &lock around zone_cond_store() in the two store wrappers to serialize dev->zones check-and-deref against its alloc/free, which already run under &lock. The reason there was no problem before is that only nullb_device_release() or null_exit() frees the dev->zones, which guarantees that subsequent users won't access the configfs interface.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90187",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "ca4b2a011948fae4e4d31490107db4926385a983",
              "lessThan": "056be41932c95aabdb3c2967d1ef4978f17a0225",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ca4b2a011948fae4e4d31490107db4926385a983",
              "lessThan": "b2437d37fcc31fce8a5da1cc1739e284814d2491",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ca4b2a011948fae4e4d31490107db4926385a983",
              "lessThan": "0a3afab87124171022fb3579502fa38ef5b311c9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ca4b2a011948fae4e4d31490107db4926385a983",
              "lessThan": "2a6357a9b935a34f5508618fee8a7fffbf7722a8",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/block/null_blk/main.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.19"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.19",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/block/null_blk/main.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:13.270",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/056be41932c95aabdb3c2967d1ef4978f17a0225",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/0a3afab87124171022fb3579502fa38ef5b311c9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2a6357a9b935a34f5508618fee8a7fffbf7722a8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b2437d37fcc31fce8a5da1cc1739e284814d2491",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnull_blk: free zones array on device power-off\n\nnull_init_zoned_dev() allocates dev->zones when a zoned device is powered\non, but null_del_dev() never frees it on power-off; dev->zones is only\nfreed later in null_free_dev(), when the configfs directory is removed. If\nthe device is powered off and then on again, null_init_zoned_dev()\nallocates a new array and overwrites the dev->zones pointer, leaking the\nprevious allocation each power cycle.\n\nFree dev->zones in null_del_dev() via null_free_zoned_dev() to solve it.\nAnd calling null_free_zoned_dev() in null_free_dev() is no longer necessary\nbecause every caller already invokes null_del_dev() first: via\nnullb_group_drop_item() before nullb_device_release(), in the\nnull_add_dev() error path of null_create_dev(), and in null_destroy_dev().\nRemove the redundant call.\n\nAnd take &lock around zone_cond_store() in the two store wrappers to\nserialize dev->zones check-and-deref against its alloc/free, which already\nrun under &lock. The reason there was no problem before is that only\nnullb_device_release() or null_exit() frees the dev->zones, which\nguarantees that subsequent users won't access the configfs interface."
    }
  ],
  "lastModified": "2026-09-17T17:17:13.270",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}