CVE-2026-90188
In the Linux kernel, the following vulnerability has been resolved:
null_blk: free global tag_set on init error path
If shared_tags is enabled, null_setup_tagset() allocates the global tag_set via null_init_global_tag_set(). If device creation later fails, err_dev destroys the default devices and calls unregister_blkdev(), but never frees the global tag_set. Since module init failed, null_exit() is never invoked, so the global tag_set's tags and maps are permanently leaked.
Free the global tag_set in err_dev, matching null_exit() which does if (tag_set.ops) blk_mq_free_tag_set(&tag_set).
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/081cf37e8a0e00cd91d6df53172c9d928790a798
- https://git.kernel.org/stable/c/0b2faa330184340d9418ad2c627c2ae881772e33
- https://git.kernel.org/stable/c/2882e1450fa4597811a951196e07553ea134eb31
- https://git.kernel.org/stable/c/2b59484ac1e64dd78dbe8c6140891c6308085a75
- https://git.kernel.org/stable/c/5a1c5ff3a49ba93a1fd0b70537e7a0164071760d
- https://git.kernel.org/stable/c/665c94554ff0d5d88caae7f40c16c8e0a3369eda
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-90188",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "82f402fefa50f1675bf918bcd009981bd6b30ac8",
"lessThan": "0b2faa330184340d9418ad2c627c2ae881772e33",
"versionType": "git"
},
{
"status": "affected",
"version": "82f402fefa50f1675bf918bcd009981bd6b30ac8",
"lessThan": "665c94554ff0d5d88caae7f40c16c8e0a3369eda",
"versionType": "git"
},
{
"status": "affected",
"version": "82f402fefa50f1675bf918bcd009981bd6b30ac8",
"lessThan": "2882e1450fa4597811a951196e07553ea134eb31",
"versionType": "git"
},
{
"status": "affected",
"version": "82f402fefa50f1675bf918bcd009981bd6b30ac8",
"lessThan": "2b59484ac1e64dd78dbe8c6140891c6308085a75",
"versionType": "git"
},
{
"status": "affected",
"version": "82f402fefa50f1675bf918bcd009981bd6b30ac8",
"lessThan": "081cf37e8a0e00cd91d6df53172c9d928790a798",
"versionType": "git"
},
{
"status": "affected",
"version": "82f402fefa50f1675bf918bcd009981bd6b30ac8",
"lessThan": "5a1c5ff3a49ba93a1fd0b70537e7a0164071760d",
"versionType": "git"
}
],
"programFiles": [
"drivers/block/null_blk/main.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.13"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.13",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.1.188",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.157",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.110",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.52",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/block/null_blk/main.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-17T17:17:13.397",
"references": [
{
"url": "https://git.kernel.org/stable/c/081cf37e8a0e00cd91d6df53172c9d928790a798",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/0b2faa330184340d9418ad2c627c2ae881772e33",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2882e1450fa4597811a951196e07553ea134eb31",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2b59484ac1e64dd78dbe8c6140891c6308085a75",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5a1c5ff3a49ba93a1fd0b70537e7a0164071760d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/665c94554ff0d5d88caae7f40c16c8e0a3369eda",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnull_blk: free global tag_set on init error path\n\nIf shared_tags is enabled, null_setup_tagset() allocates the global tag_set\nvia null_init_global_tag_set(). If device creation later fails, err_dev\ndestroys the default devices and calls unregister_blkdev(), but never frees\nthe global tag_set. Since module init failed, null_exit() is never invoked,\nso the global tag_set's tags and maps are permanently leaked.\n\nFree the global tag_set in err_dev, matching null_exit() which does\nif (tag_set.ops) blk_mq_free_tag_set(&tag_set)."
}
],
"lastModified": "2026-09-17T17:17:13.397",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}