Impact
The null_blk driver in the Linux kernel implements configuration via configfs. Store callbacks for attributes such as submit_queues and poll_queues execute without acquiring the necessary lock, whereas configfs only serializes writes for a single file descriptor. Consequently, two concurrent writes to different file descriptors can race, allowing a second write to overwrite device state after the first applies changes. For attributes that do not use an apply_fn, such as power_store, there is a narrow window where a write can modify internal fields before the driver finishes its setup, potentially pushing parameters beyond their intended bounds. The result is kernel memory corruption, which can manifest as warnings, crashes, or, if fully exploited, privilege escalation for the writing process.
Affected Systems
This flaw resides in the generic null_blk driver code that is compiled into the Linux kernel across all distributions. The advisories do not list specific kernel versions, implying that any kernel builds that expose the null_blk configfs interface and allow write access to its attributes are affected. Systems that have disabled the null_blk driver or restrict configfs write permissions are not impacted.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not present in the CISA KEV catalog, indicating a low likelihood of widespread exploitation. However, the flaw requires local write access to the configfs entries, which is normally confined to privileged users. If an attacker can perform the race, kernel memory corruption could be achieved, leading to a crash or possibly a privilege escalation. The overall risk is moderate, concentrated on systems that expose the vulnerable driver and allow unrestricted configfs writes.
OpenCVE Enrichment
Debian DLA
Debian DSA