{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90187","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.791Z","datePublished":"2026-09-17T16:07:09.683Z","dateUpdated":"2026-09-17T16:07:09.683Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-17T16:07:09.683Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnull_blk: free zones array on device power-off\n\nnull_init_zoned_dev() allocates dev->zones when a zoned device is powered\non, but null_del_dev() never frees it on power-off; dev->zones is only\nfreed later in null_free_dev(), when the configfs directory is removed. If\nthe device is powered off and then on again, null_init_zoned_dev()\nallocates a new array and overwrites the dev->zones pointer, leaking the\nprevious allocation each power cycle.\n\nFree dev->zones in null_del_dev() via null_free_zoned_dev() to solve it.\nAnd calling null_free_zoned_dev() in null_free_dev() is no longer necessary\nbecause every caller already invokes null_del_dev() first: via\nnullb_group_drop_item() before nullb_device_release(), in the\nnull_add_dev() error path of null_create_dev(), and in null_destroy_dev().\nRemove the redundant call.\n\nAnd take &lock around zone_cond_store() in the two store wrappers to\nserialize dev->zones check-and-deref against its alloc/free, which already\nrun under &lock. The reason there was no problem before is that only\nnullb_device_release() or null_exit() frees the dev->zones, which\nguarantees that subsequent users won't access the configfs interface."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/block/null_blk/main.c"],"versions":[{"version":"ca4b2a011948fae4e4d31490107db4926385a983","lessThan":"056be41932c95aabdb3c2967d1ef4978f17a0225","status":"affected","versionType":"git"},{"version":"ca4b2a011948fae4e4d31490107db4926385a983","lessThan":"b2437d37fcc31fce8a5da1cc1739e284814d2491","status":"affected","versionType":"git"},{"version":"ca4b2a011948fae4e4d31490107db4926385a983","lessThan":"0a3afab87124171022fb3579502fa38ef5b311c9","status":"affected","versionType":"git"},{"version":"ca4b2a011948fae4e4d31490107db4926385a983","lessThan":"2a6357a9b935a34f5508618fee8a7fffbf7722a8","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/block/null_blk/main.c"],"versions":[{"version":"4.19","status":"affected"},{"version":"0","lessThan":"4.19","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/056be41932c95aabdb3c2967d1ef4978f17a0225"},{"url":"https://git.kernel.org/stable/c/b2437d37fcc31fce8a5da1cc1739e284814d2491"},{"url":"https://git.kernel.org/stable/c/0a3afab87124171022fb3579502fa38ef5b311c9"},{"url":"https://git.kernel.org/stable/c/2a6357a9b935a34f5508618fee8a7fffbf7722a8"}],"title":"null_blk: free zones array on device power-off","x_generator":{"engine":"bippy-1.2.0"}}}}