Impact
The null_blk block driver in the Linux kernel suffers from a NULL pointer dereference when a per‑device queue size change is attempted on a device bound to a shared tag set. The driver incorrectly falls back to generic queue structures, leaving some queue contexts NULL. When the kernel later attempts to map these NULL contexts to CPUs, a KASAN‑reported null pointer dereference occurs, leading to a kernel panic. This is a local denial‑of‑service vulnerability that requires the ability to write to the null_blk configuration via configfs.
Affected Systems
The vulnerability affects Linux kernel builds that enable the null_blk module with the shared_tags parameter set to 1. Any kernel version that includes the unpatched null_blk driver and permits runtime resizing of submit_queues or poll_queues is susceptible. The exact kernel version range is not specified in the advisory, but the issue was observed in a 7.2.0‑rc2+ build. The impact is confined to systems running the affected kernel and the null_blk driver.
Risk and Exploitability
The EPSS figure is below 1%, and the vulnerability is not listed in the CISA KEV catalog, implying a low overall exploitation probability. Attackers would need local or root access to adjust the queue parameters via configfs, which limits the threat surface. Nonetheless, the crash can disrupt critical services on a compromised host, so the advisory recommends applying the kernel patch that rejects per‑device queue resizes with an EINVAL return value.
OpenCVE Enrichment
Debian DLA
Debian DSA