-

CVE-2026-90190

null_blk: use DEFINE_MUTEX for the file-scope mutex

In the Linux kernel, the following vulnerability has been resolved:

null_blk: use DEFINE_MUTEX for the file-scope mutex

In null_init(), mutex_init(&lock) currently happens after
configfs_register_subsystem(), which exposes the nullb subsystem to
userspace. A racing mkdir() into /sys/kernel/config/nullb/ can reach
null_find_dev_by_name() -> mutex_lock(&lock) before the mutex is
initialized, trigger warning:

[  123.137788] DEBUG_LOCKS_WARN_ON(lock->magic != lock)
[  123.137796] WARNING: kernel/locking/mutex.c:159 at mutex_lock+0x171/0x1c0, CPU#13: mkdir/1301
[  123.140090] Modules linked in: null_blk(+) nft_fib_inet nft_fib_ipv4
......
[  123.154926] Call Trace:
[  123.155172]  <TASK>
[  123.155419]  ? __pfx_mutex_lock+0x10/0x10
[  123.156181]  ? __pfx__raw_spin_lock+0x10/0x10
[  123.156571]  nullb_group_make_group+0x20/0x100 [null_blk]
[  123.157011]  configfs_mkdir+0x47b/0xc70
[  123.157337]  ? __pfx_configfs_mkdir+0x10/0x10
[  123.157719]  ? may_create_dentry+0x242/0x2e0
[  123.158061]  vfs_mkdir+0x2a9/0x6c0
[  123.158352]  filename_mkdirat+0x3dc/0x500
[  123.158710]  ? __pfx_filename_mkdirat+0x10/0x10
[  123.159070]  ? strncpy_from_user+0x3a/0x1d0
[  123.159413]  __x64_sys_mkdir+0x6b/0x90
[  123.159760]  do_syscall_64+0xea/0x600

Replace the runtime mutex_init(&lock) with a static DEFINE_MUTEX(lock)
declaration to fix this issue.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 49c3b9266a718dbd73c42e004288b4bb2ea0ac0b
Version < f9f4ca45c770b7eec83fea6c9b727b26e691b513
Status affected
Version 49c3b9266a718dbd73c42e004288b4bb2ea0ac0b
Version < 349903f7ee72f7ac5b7a98840d701b2082d140a3
Status affected
Version 49c3b9266a718dbd73c42e004288b4bb2ea0ac0b
Version < 0a8c2f7b95981913ac370683e34db4906970c210
Status affected
Version 49c3b9266a718dbd73c42e004288b4bb2ea0ac0b
Version < c7dea90c9b4ef1dfbd2e4df36de180c76fd7c33c
Status affected
Version 49c3b9266a718dbd73c42e004288b4bb2ea0ac0b
Version < 234117949da3b3f9705a21b66094f9f30bbe681d
Status affected
Version 49c3b9266a718dbd73c42e004288b4bb2ea0ac0b
Version < 017dac7670909eaea3eb36e6b3b5a8be9ce0a14d
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.19
Status affected
Version 0
Version < 5.19
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.109
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/f9f4ca45c770b7eec83fea6c9b727b26e691b513
https://git.kernel.org/stable/c/349903f7ee72f7ac5b7a98840d701b2082d140a3
https://git.kernel.org/stable/c/0a8c2f7b95981913ac370683e34db4906970c210
https://git.kernel.org/stable/c/c7dea90c9b4ef1dfbd2e4df36de180c76fd7c33c
https://git.kernel.org/stable/c/234117949da3b3f9705a21b66094f9f30bbe681d
https://git.kernel.org/stable/c/017dac7670909eaea3eb36e6b3b5a8be9ce0a14d