-

CVE-2026-90187

null_blk: free zones array on device power-off

In the Linux kernel, the following vulnerability has been resolved:

null_blk: free zones array on device power-off

null_init_zoned_dev() allocates dev->zones when a zoned device is powered
on, but null_del_dev() never frees it on power-off; dev->zones is only
freed later in null_free_dev(), when the configfs directory is removed. If
the device is powered off and then on again, null_init_zoned_dev()
allocates a new array and overwrites the dev->zones pointer, leaking the
previous allocation each power cycle.

Free dev->zones in null_del_dev() via null_free_zoned_dev() to solve it.
And calling null_free_zoned_dev() in null_free_dev() is no longer necessary
because every caller already invokes null_del_dev() first: via
nullb_group_drop_item() before nullb_device_release(), in the
null_add_dev() error path of null_create_dev(), and in null_destroy_dev().
Remove the redundant call.

And take &lock around zone_cond_store() in the two store wrappers to
serialize dev->zones check-and-deref against its alloc/free, which already
run under &lock. The reason there was no problem before is that only
nullb_device_release() or null_exit() frees the dev->zones, which
guarantees that subsequent users won't access the configfs interface.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version ca4b2a011948fae4e4d31490107db4926385a983
Version < 056be41932c95aabdb3c2967d1ef4978f17a0225
Status affected
Version ca4b2a011948fae4e4d31490107db4926385a983
Version < b2437d37fcc31fce8a5da1cc1739e284814d2491
Status affected
Version ca4b2a011948fae4e4d31490107db4926385a983
Version < 0a3afab87124171022fb3579502fa38ef5b311c9
Status affected
Version ca4b2a011948fae4e4d31490107db4926385a983
Version < 2a6357a9b935a34f5508618fee8a7fffbf7722a8
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.19
Status affected
Version 0
Version < 4.19
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.102
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/056be41932c95aabdb3c2967d1ef4978f17a0225
https://git.kernel.org/stable/c/b2437d37fcc31fce8a5da1cc1739e284814d2491
https://git.kernel.org/stable/c/0a3afab87124171022fb3579502fa38ef5b311c9
https://git.kernel.org/stable/c/2a6357a9b935a34f5508618fee8a7fffbf7722a8