PT-2026-94533 · Linux · Linux Kernel

CVE-2026-90185

·

Published

2026-09-17

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the null blk driver where configfs attribute stores are not properly serialized with a lock. This occurs because the NULLB DEVICE ATTR store does not utilize a lock, allowing concurrent stores on separate file descriptors to race. For attributes using apply fn, such as submit queues and poll queues, a race condition can cause dev->NAME to be overwritten after the function returns, leading to a synchronization failure between dev->submit queues and the live queue count, which is detected by the null map queues() function.
For attributes without apply fn, a race condition during the null add dev() process in power store() can allow a field to be modified mid-setup. For instance, the zone nr conv variable could be increased beyond nr zones after being clamped, resulting in an out-of-bounds access to the dev->zones[] array.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102582
CVE-2026-90185
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel