{"id":"CVE-2026-90184","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nnull_blk: serialize configfs attribute updates with device setup\n\nThe attribute store methods generated with NULLB_DEVICE_ATTR() refuse to\nchange the configuration of a…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nnull_blk: serialize configfs attribute updates with device setup\n\nThe attribute store methods generated with NULLB_DEVICE_ATTR() refuse to\nchange the configuration of a…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 3bf2bd20734e3e6ffda53719a9c10fb3ee9c5ffa < 6352e7ead2d8111802a554eeb94886f5a9894bb9","Linux >= 3bf2bd20734e3e6ffda53719a9c10fb3ee9c5ffa < 7de792b4c48fba02a36a8077032f7d5093c925e5","Linux >= 3bf2bd20734e3e6ffda53719a9c10fb3ee9c5ffa < aed8af338a09a64d63b068a803c4ecfc5701dd4c","Linux >= 3bf2bd20734e3e6ffda53719a9c10fb3ee9c5ffa < 32456a85995579e56c60cc53c357cda75a9d4f7c","Linux >= 3bf2bd20734e3e6ffda53719a9c10fb3ee9c5ffa < d3d35dd045a35991bf6fd13de5f293e6dd7bf3b3","Linux >= 3bf2bd20734e3e6ffda53719a9c10fb3ee9c5ffa < 4e1f23f9c33c156be7e313b40695af5a3a834739","Linux 4.14"],"published":"2026-09-17","updated":"2026-09-17","sourceUpdated":"2026-09-17T17:17:12.833","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90184","references":[{"url":"https://git.kernel.org/stable/c/32456a85995579e56c60cc53c357cda75a9d4f7c","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4e1f23f9c33c156be7e313b40695af5a3a834739","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6352e7ead2d8111802a554eeb94886f5a9894bb9","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7de792b4c48fba02a36a8077032f7d5093c925e5","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aed8af338a09a64d63b068a803c4ecfc5701dd4c","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d3d35dd045a35991bf6fd13de5f293e6dd7bf3b3","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-17T16:21:47.865Z","epss":0.00205,"epssPercentile":0.10895,"slug":"CVE-2026-90184","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnull_blk: serialize configfs attribute updates with device setup\n\nThe attribute store methods generated with NULLB_DEVICE_ATTR() refuse to\nchange the configuration of a live device by testing\nNULLB_DEV_FL_CONFIGURED, but that flag is only set by\nnullb_device_power_store() after null_add_dev() has returned, and the\nstore methods take no lock at all. configfs only serializes writes to\nthe same open file (buffer->mutex), so a write to any attribute can run\nconcurrently with null_add_dev() and change the device configuration\nwhile it is being used.\n\nnull_add_dev() reads the configuration several times, e.g. dev->zoned is\nread once to set up the queue limits and once to initialize the zone\nresources:\n\n  CPU0: echo 1 > nullb0/power         CPU1: echo 1 > nullb0/zoned\n  nullb_device_power_store()\n    mutex_lock(&lock)\n    null_add_dev()\n      if (dev->zoned) -> false\n        /* no BLK_FEAT_ZONED */       nullb_device_zoned_store()\n                                        test_bit(FL_CONFIGURED) -> 0\n                                        dev->zoned = true\n      blk_mq_alloc_disk()\n        /* queue is not zoned */\n      if (nullb->dev->zoned) -> true\n        null_register_zoned_dev()\n          blk_revalidate_disk_zones()\n\nblk_revalidate_disk_zones() is then called for a queue that does not\nhave BLK_FEAT_ZONED set, which triggers its WARN_ON_ONCE() and fails the\ndevice setup with -EIO:\n\n  WARNING: CPU: 2 PID: 322 at block/blk-zoned.c:2357 blk_revalidate_disk_zones+0x4c/0x560\n\nClearing dev->zoned in the same window is worse: the queue is created\nwith BLK_FEAT_ZONED but the zone resources are never initialized, so\nadd_disk() succeeds for a zoned disk that has no zones. And a store that\nlands after the last dev->zoned test leaves dev->zoned set while\ndev->zones is still NULL, which null_process_zoned_cmd() dereferences on\nthe first write.\n\nFix this by taking the global lock, which nullb_device_power_store()\nalready holds across null_add_dev() and null_del_dev(), around both the\nNULLB_DEV_FL_CONFIGURED test and the update of the device configuration.\nThe submit_queues and poll_queues apply callbacks are now called with\nthat lock held, so remove the locking they did themselves.\n\nSince the store methods can run as soon as configfs_register_subsystem()\nreturns, that is, before null_init() gets to mutex_init(&lock), also\ninitialize the lock statically with DEFINE_MUTEX().\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}