PT-2026-94533 · Linux · Linux Kernel
CVE-2026-90185
·
Published
2026-09-17
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the
null blk driver where configfs attribute stores are not properly serialized with a lock. This occurs because the NULLB DEVICE ATTR store does not utilize a lock, allowing concurrent stores on separate file descriptors to race. For attributes using apply fn, such as submit queues and poll queues, a race condition can cause dev->NAME to be overwritten after the function returns, leading to a synchronization failure between dev->submit queues and the live queue count, which is detected by the null map queues() function.For attributes without
apply fn, a race condition during the null add dev() process in power store() can allow a field to be modified mid-setup. For instance, the zone nr conv variable could be increased beyond nr zones after being clamped, resulting in an out-of-bounds access to the dev->zones[] array.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel