CVE-2026-90187

Source
https://cve.org/CVERecord?id=CVE-2026-90187
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90187.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90187
Downstream
Published
2026-09-17T16:07:09Z
Modified
2026-09-19T03:47:25Z
Summary
null_blk: free zones array on device power-off
Details

In the Linux kernel, the following vulnerability has been resolved:

null_blk: free zones array on device power-off

null_init_zoned_dev() allocates dev->zones when a zoned device is powered on, but null_del_dev() never frees it on power-off; dev->zones is only freed later in null_free_dev(), when the configfs directory is removed. If the device is powered off and then on again, null_init_zoned_dev() allocates a new array and overwrites the dev->zones pointer, leaking the previous allocation each power cycle.

Free dev->zones in null_del_dev() via null_free_zoned_dev() to solve it. And calling null_free_zoned_dev() in null_free_dev() is no longer necessary because every caller already invokes null_del_dev() first: via nullb_group_drop_item() before nullb_device_release(), in the null_add_dev() error path of null_create_dev(), and in null_destroy_dev(). Remove the redundant call.

And take &lock around zone_cond_store() in the two store wrappers to serialize dev->zones check-and-deref against its alloc/free, which already run under &lock. The reason there was no problem before is that only nullb_device_release() or null_exit() frees the dev->zones, which guarantees that subsequent users won't access the configfs interface.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90187.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ca4b2a011948fae4e4d31490107db4926385a983
Fixed
056be41932c95aabdb3c2967d1ef4978f17a0225
Fixed
b2437d37fcc31fce8a5da1cc1739e284814d2491
Fixed
0a3afab87124171022fb3579502fa38ef5b311c9
Fixed
2a6357a9b935a34f5508618fee8a7fffbf7722a8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90187.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.19.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90187.json"