-

CVE-2026-90189

null_blk: register configfs subsystem after creating default devices

In the Linux kernel, the following vulnerability has been resolved:

null_blk: register configfs subsystem after creating default devices

In null_init(), configfs_register_subsystem() currently runs before
register_blkdev(), so when null_blk is built as a module, a racing mkdir()
+ poweron from userspace can reach null_add_dev() while null_major is still
0. __add_disk() then hits WARN_ON(disk->minors) (major=0 with minors!=0)
and fails:

[root@fedora ~]# [ 2366.521436] WARNING: block/genhd.c:476 at __add_disk+0x8a7/0xde0,
[ 2366.523552] Modules linked in: null_blk(+) nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib
[ 2366.529081] CPU: 26 UID: 0 PID: 1600 Comm: sh Not tainted 7.2.0-rc1+ #66 PREEMPT(full)
......
[ 2366.547251] Call Trace:
[ 2366.547575]  <TASK>
[ 2366.547831]  ? _raw_spin_lock+0x84/0xe0
[ 2366.548260]  add_disk_fwnode+0x114/0x560
[ 2366.548739]  null_add_dev+0x102d/0x1b80 [null_blk]
[ 2366.549310]  ? __pfx_null_add_dev+0x10/0x10 [null_blk]
[ 2366.549906]  ? mutex_lock+0xde/0x1c0
[ 2366.550361]  ? __pfx_mutex_lock+0x10/0x10
[ 2366.550827]  nullb_device_power_store+0x1e7/0x280 [null_blk]
[ 2366.551499]  ? __pfx_nullb_device_power_store+0x10/0x10 [null_blk]
[ 2366.552177]  ? __kmalloc_cache_noprof+0x1f5/0x470
[ 2366.552748]  ? configfs_write_iter+0x35c/0x4e0
[ 2366.553242]  configfs_write_iter+0x286/0x4e0
[ 2366.553787]  vfs_write+0x52d/0xd00
[ 2366.554169]  ? __pfx_vfs_write+0x10/0x10
[ 2366.554679]  ? __pfx___css_rstat_updated+0x10/0x10
[ 2366.555196]  ? fdget_pos+0x1cf/0x4c0
[ 2366.555649]  ksys_write+0xfc/0x1d0
......

Additionally, the err_dev path destroys all devices on nullb_list while
configfs is still registered. If a racing mkdir() + poweron puts a user
device on the list, null_destroy_dev()->null_free_dev() kfrees the user
device's nullb_device but /sys/kernel/config/nullb/<name> is still
reachable. Any userspace access to the item will trigger a UAF.

For simplicity, move configfs_register_subsystem() to the end to solve
the problems above.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 3bf2bd20734e3e6ffda53719a9c10fb3ee9c5ffa
Version < 2679b11e9256bd70a5ef41783bab6ad6c34a3db1
Status affected
Version 3bf2bd20734e3e6ffda53719a9c10fb3ee9c5ffa
Version < dbcedbe4819ae21274ea77469e61e46a878b9943
Status affected
Version 3bf2bd20734e3e6ffda53719a9c10fb3ee9c5ffa
Version < 57debc907aef66319d244009d3370dcd97388d37
Status affected
Version 3bf2bd20734e3e6ffda53719a9c10fb3ee9c5ffa
Version < d761be1b8f2bbabc41252deb79a426d3f0d4fa10
Status affected
Version 3bf2bd20734e3e6ffda53719a9c10fb3ee9c5ffa
Version < cab9bf5f68f76cd44e0ec92bd4a60c9b83656a36
Status affected
Version 3bf2bd20734e3e6ffda53719a9c10fb3ee9c5ffa
Version < c9d293d6bb0575fcb1f3408129453187e2a28a4e
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.14
Status affected
Version 0
Version < 4.14
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.07
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/2679b11e9256bd70a5ef41783bab6ad6c34a3db1
https://git.kernel.org/stable/c/dbcedbe4819ae21274ea77469e61e46a878b9943
https://git.kernel.org/stable/c/57debc907aef66319d244009d3370dcd97388d37
https://git.kernel.org/stable/c/d761be1b8f2bbabc41252deb79a426d3f0d4fa10
https://git.kernel.org/stable/c/cab9bf5f68f76cd44e0ec92bd4a60c9b83656a36
https://git.kernel.org/stable/c/c9d293d6bb0575fcb1f3408129453187e2a28a4e