PT-2026-94538 · Linux · Linux Kernel
CVE-2026-90190
·
Published
2026-09-17
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
In the
null blk component, a race condition exists during initialization. The mutex init(&lock) function is called after configfs register subsystem(), which exposes the nullb subsystem to userspace. This allows a concurrent mkdir() operation in /sys/kernel/config/nullb/ to reach the null find dev by name() function and attempt to execute mutex lock(&lock) before the mutex has been properly initialized, resulting in a kernel warning.Recommendations
Replace the runtime
mutex init(&lock) call with a static DEFINE MUTEX(lock) declaration.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel