« Volver al listado

CVE-2026-90189

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

null_blk: register configfs subsystem after creating default devices

In null_init(), configfs_register_subsystem() currently runs before register_blkdev(), so when null_blk is built as a module, a racing mkdir() + poweron from userspace can reach null_add_dev() while null_major is still 0. __add_disk() then hits WARN_ON(disk->minors) (major=0 with minors!=0) and fails:

Additionally, the err_dev path destroys all devices on nullb_list while configfs is still registered.

Leer descripción completaMostrar menos

If a racing mkdir() + poweron puts a user device on the list, null_destroy_dev()->null_free_dev() kfrees the user device's nullb_device but /sys/kernel/config/nullb/<name> is still reachable. Any userspace access to the item will trigger a UAF.

For simplicity, move configfs_register_subsystem() to the end to solve the problems above.

Detalles técnicos trazas, registros y código del informe original
[root@fedora ~]# [ 2366.521436] WARNING: block/genhd.c:476 at __add_disk+0x8a7/0xde0,
[ 2366.523552] Modules linked in: null_blk(+) nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib
[ 2366.529081] CPU: 26 UID: 0 PID: 1600 Comm: sh Not tainted 7.2.0-rc1+ #66 PREEMPT(full)
......
[ 2366.547251] Call Trace:
[ 2366.547575]  <TASK>
[ 2366.547831]  ? _raw_spin_lock+0x84/0xe0
[ 2366.548260]  add_disk_fwnode+0x114/0x560
[ 2366.548739]  null_add_dev+0x102d/0x1b80 [null_blk]
[ 2366.549310]  ? __pfx_null_add_dev+0x10/0x10 [null_blk]
[ 2366.549906]  ? mutex_lock+0xde/0x1c0
[ 2366.550361]  ? __pfx_mutex_lock+0x10/0x10
[ 2366.550827]  nullb_device_power_store+0x1e7/0x280 [null_blk]
[ 2366.551499]  ? __pfx_nullb_device_power_store+0x10/0x10 [null_blk]
[ 2366.552177]  ? __kmalloc_cache_noprof+0x1f5/0x470
[ 2366.552748]  ? configfs_write_iter+0x35c/0x4e0
[ 2366.553242]  configfs_write_iter+0x286/0x4e0
[ 2366.553787]  vfs_write+0x52d/0xd00
[ 2366.554169]  ? __pfx_vfs_write+0x10/0x10
[ 2366.554679]  ? __pfx___css_rstat_updated+0x10/0x10
[ 2366.555196]  ? fdget_pos+0x1cf/0x4c0
[ 2366.555649]  ksys_write+0xfc/0x1d0
......

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90189",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3bf2bd20734e3e6ffda53719a9c10fb3ee9c5ffa",
              "lessThan": "2679b11e9256bd70a5ef41783bab6ad6c34a3db1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3bf2bd20734e3e6ffda53719a9c10fb3ee9c5ffa",
              "lessThan": "dbcedbe4819ae21274ea77469e61e46a878b9943",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3bf2bd20734e3e6ffda53719a9c10fb3ee9c5ffa",
              "lessThan": "57debc907aef66319d244009d3370dcd97388d37",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3bf2bd20734e3e6ffda53719a9c10fb3ee9c5ffa",
              "lessThan": "d761be1b8f2bbabc41252deb79a426d3f0d4fa10",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3bf2bd20734e3e6ffda53719a9c10fb3ee9c5ffa",
              "lessThan": "cab9bf5f68f76cd44e0ec92bd4a60c9b83656a36",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3bf2bd20734e3e6ffda53719a9c10fb3ee9c5ffa",
              "lessThan": "c9d293d6bb0575fcb1f3408129453187e2a28a4e",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/block/null_blk/main.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.14"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.14",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/block/null_blk/main.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:13.533",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/2679b11e9256bd70a5ef41783bab6ad6c34a3db1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/57debc907aef66319d244009d3370dcd97388d37",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c9d293d6bb0575fcb1f3408129453187e2a28a4e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cab9bf5f68f76cd44e0ec92bd4a60c9b83656a36",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d761be1b8f2bbabc41252deb79a426d3f0d4fa10",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/dbcedbe4819ae21274ea77469e61e46a878b9943",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnull_blk: register configfs subsystem after creating default devices\n\nIn null_init(), configfs_register_subsystem() currently runs before\nregister_blkdev(), so when null_blk is built as a module, a racing mkdir()\n+ poweron from userspace can reach null_add_dev() while null_major is still\n0. __add_disk() then hits WARN_ON(disk->minors) (major=0 with minors!=0)\nand fails:\n\n[root@fedora ~]# [ 2366.521436] WARNING: block/genhd.c:476 at __add_disk+0x8a7/0xde0,\n[ 2366.523552] Modules linked in: null_blk(+) nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib\n[ 2366.529081] CPU: 26 UID: 0 PID: 1600 Comm: sh Not tainted 7.2.0-rc1+ #66 PREEMPT(full)\n......\n[ 2366.547251] Call Trace:\n[ 2366.547575]  <TASK>\n[ 2366.547831]  ? _raw_spin_lock+0x84/0xe0\n[ 2366.548260]  add_disk_fwnode+0x114/0x560\n[ 2366.548739]  null_add_dev+0x102d/0x1b80 [null_blk]\n[ 2366.549310]  ? __pfx_null_add_dev+0x10/0x10 [null_blk]\n[ 2366.549906]  ? mutex_lock+0xde/0x1c0\n[ 2366.550361]  ? __pfx_mutex_lock+0x10/0x10\n[ 2366.550827]  nullb_device_power_store+0x1e7/0x280 [null_blk]\n[ 2366.551499]  ? __pfx_nullb_device_power_store+0x10/0x10 [null_blk]\n[ 2366.552177]  ? __kmalloc_cache_noprof+0x1f5/0x470\n[ 2366.552748]  ? configfs_write_iter+0x35c/0x4e0\n[ 2366.553242]  configfs_write_iter+0x286/0x4e0\n[ 2366.553787]  vfs_write+0x52d/0xd00\n[ 2366.554169]  ? __pfx_vfs_write+0x10/0x10\n[ 2366.554679]  ? __pfx___css_rstat_updated+0x10/0x10\n[ 2366.555196]  ? fdget_pos+0x1cf/0x4c0\n[ 2366.555649]  ksys_write+0xfc/0x1d0\n......\n\nAdditionally, the err_dev path destroys all devices on nullb_list while\nconfigfs is still registered. If a racing mkdir() + poweron puts a user\ndevice on the list, null_destroy_dev()->null_free_dev() kfrees the user\ndevice's nullb_device but /sys/kernel/config/nullb/<name> is still\nreachable. Any userspace access to the item will trigger a UAF.\n\nFor simplicity, move configfs_register_subsystem() to the end to solve\nthe problems above."
    }
  ],
  "lastModified": "2026-09-17T17:17:13.533",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}