CVE-2026-90187
CVE CVE-2026-90187EUVD EUVD-2026-81780Published 2026-09-17T16:07:09.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: null_blk: free zones array on device power-off null_init_zoned_dev() allocates dev->zones when a zoned device is powered on, but null_del_dev() never frees it on power-off; dev->zones is only freed later in null_free_dev(), when the configfs directory is removed. If the device is powered off and then on again, null_init_zoned_dev() allocates a new array and overwrites the dev->zones pointer, leaking the previous allocation each power cycle. Free dev->zones in null_del_dev() via null_free_zoned_dev() to solve it. And calling null_free_zoned_dev() in null_free_dev() is no longer necessary because every caller already invokes null_del_dev() first: via nullb_group_drop_item() before nullb_device_release(), in the null_add_dev() error path of null_create_dev(), and in null_destroy_dev(). Remove the redundant call. And take &lock around zone_cond_store() in the two store wrappers to serialize dev->zones check-and-deref against its alloc/free, which already run under &lock. The reason there was no problem before is that only nullb_device_release() or null_exit() frees the dev->zones, which guarantees that subsequent users won't access the configfs interface.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux ca4b2a011948fae4e4d31490107db4926385a983 <b2437d37fcc31fce8a5da1cc1739e284814d2491; patch: 6.18.52; patch: 0; ca4b2a011948fae4e4d31490107db4926385a983 <056be41932c95aabdb3c2967d1ef4978f17a0225; patch: 7.2.6; ca4b2a011948fae4e4d31490107db4926385a983 <2a6357a9b935a34f5508618fee8a7fffbf7722a8; 4.19; patch: 6.12.110; ca4b2a011948fae4e4d31490107db4926385a983 <0a3afab87124171022fb3579502fa38ef5b311c9; patch: 7.3-rc1
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.