-

CVE-2026-90185

null_blk: serialize configfs attribute stores with the lock

In the Linux kernel, the following vulnerability has been resolved:

null_blk: serialize configfs attribute stores with the lock

The NULLB_DEVICE_ATTR _store takes no lock: apply_fn attributes
(submit_queues, poll_queues) get dev->NAME written again after apply_fn
returns, outside its lock; APPLY=NULL attributes are entirely lockless.
configfs only serializes stores per-open-file, so concurrent stores on
separate fds race.

For apply_fn attributes, once one store's apply_fn has reconfigured the
hardware, a second (losing) store can still overwrite dev->NAME
afterwards. This leaves dev->submit_queues out of sync with the live
queue count, which is later caught by the WARN_ON_ONCE() in
null_map_queues().

For !apply_fn attributes, power_store()'s null_add_dev() validates and
builds the device under "lock" but only sets CONFIGURED afterwards. A store
slipping in during this window can change a field mid-setup -- for example,
zone_nr_conv can be pushed above nr_zones after it has already been
clamped, leading to an out-of-bounds dev->zones[] access.

Take "lock" in the macro around the apply_fn call, the CONFIGURED test and
the field write, and move it out of nullb_apply_submit_queues()/
nullb_apply_poll_queues() so both paths are covered once. This serializes
stores with power_store's setup and with each other.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 45919fbfe1c487c17ea1d198534339a5e8abeae3
Version < 8e839ed5210399a0330a8a6c5885c1d40a537c6d
Status affected
Version 45919fbfe1c487c17ea1d198534339a5e8abeae3
Version < 88d806d0e1d36246208386a8e55b511c1b3d647c
Status affected
Version 45919fbfe1c487c17ea1d198534339a5e8abeae3
Version < 3945ce8cbce4e328e6fdf0b522dc71e340de19db
Status affected
Version 45919fbfe1c487c17ea1d198534339a5e8abeae3
Version < 65cae82fd3c39b53430672cb9e3ecd267471a6ce
Status affected
Version 45919fbfe1c487c17ea1d198534339a5e8abeae3
Version < c70994c2862b05e44728912b2ea9487d31e2aea7
Status affected
Version 45919fbfe1c487c17ea1d198534339a5e8abeae3
Version < 7e7fff51808237703a3a1df6dd5cae1dfd1db86d
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.5
Status affected
Version 0
Version < 5.5
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.109
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/8e839ed5210399a0330a8a6c5885c1d40a537c6d
https://git.kernel.org/stable/c/88d806d0e1d36246208386a8e55b511c1b3d647c
https://git.kernel.org/stable/c/3945ce8cbce4e328e6fdf0b522dc71e340de19db
https://git.kernel.org/stable/c/65cae82fd3c39b53430672cb9e3ecd267471a6ce
https://git.kernel.org/stable/c/c70994c2862b05e44728912b2ea9487d31e2aea7
https://git.kernel.org/stable/c/7e7fff51808237703a3a1df6dd5cae1dfd1db86d