Impact
The null_blk driver in the Linux kernel contains a race condition that permits a concurrently executed configfs attribute write to alter a live block device's configuration. Store functions generated by NULLB_DEVICE_ATTR() lack a lock and postpone setting the NULLB_DEV_FL_CONFIGURED flag until after null_add_dev() returns, so an attacker who can write to the device's configfs attributes can change the zoned or power state while the device is in use. The resulting internal state inconsistency triggers WARN_ON_ONCE in blk_revalidate_disk_zones() or causes a null‑pointer dereference in null_process_zoned_cmd(), leading the kernel to log an error, return -EIO, or in some paths crash, effectively denying service to the device.
Affected Systems
The flaw exists in every Linux kernel that includes the null_blk pseudo block device driver before the commit that introduces a global mutex around configuration changes. It applies to all distributions that ship the in‑tree null_blk module, with no specific version boundaries listed in the advisory.
Risk and Exploitability
The vulnerability has a very low probability of being exploited, as shown by an EPSS score below 1% and the fact that it is not listed in the CISA Known Exploited Vulnerabilities catalog. It requires the ability to write to configfs attributes—normally root or a privileged user—and is not remotely exploitable. Although the flaw can cause kernel panic or device failure, the overall risk is limited to systems with broad configuration access.
OpenCVE Enrichment
Debian DLA
Debian DSA