Description
In the Linux kernel, the following vulnerability has been resolved:

null_blk: free zones array on device power-off

null_init_zoned_dev() allocates dev->zones when a zoned device is powered
on, but null_del_dev() never frees it on power-off; dev->zones is only
freed later in null_free_dev(), when the configfs directory is removed. If
the device is powered off and then on again, null_init_zoned_dev()
allocates a new array and overwrites the dev->zones pointer, leaking the
previous allocation each power cycle.

Free dev->zones in null_del_dev() via null_free_zoned_dev() to solve it.
And calling null_free_zoned_dev() in null_free_dev() is no longer necessary
because every caller already invokes null_del_dev() first: via
nullb_group_drop_item() before nullb_device_release(), in the
null_add_dev() error path of null_create_dev(), and in null_destroy_dev().
Remove the redundant call.

And take &lock around zone_cond_store() in the two store wrappers to
serialize dev->zones check-and-deref against its alloc/free, which already
run under &lock. The reason there was no problem before is that only
nullb_device_release() or null_exit() frees the dev->zones, which
guarantees that subsequent users won't access the configfs interface.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Resource Exhaustion
Action: Apply Patch
AI Analysis

Impact

This bug occurs in the null_blk block‑device driver when a zoned device is powered off; the kernel allocates an array of zones in null_init_zoned_dev() but never frees that memory in null_del_dev(). Each power cycle allocates a new array and the previous one is never reclaimed. Over time the leaked memory can grow until system resources are exhausted, potentially leading to a denial‑of‑service condition. The weakness is a classic memory‑leak vulnerability (CWE‑401). It does not directly compromise confidentiality or integrity, but repeated use of the affected driver can degrade overall system stability.

Affected Systems

The flaw resides in the Linux kernel’s null_blk driver. The affected products are any Linux kernel that includes null_blk, the test data does not provide a specific kernel version, but any system that enables the null_blk subsystem with zoned devices is potentially impacted.

Risk and Exploitability

The exploit probability reported by EPSS is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, indicating a low likelihood of widespread exploitation. However, the attack vector requires local system control to repeatedly power the device on and off, which is plausible for an attacker with physical or privileged access. The potential denial‑of‑service impact makes this a moderate risk for environments that rely heavily on null_blk zoned devices.

Generated by OpenCVE AI on September 20, 2026 at 02:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version that includes the null_free_zoned_dev fix in null_del_dev and removes the redundant call in null_free_dev.
  • If an immediate kernel upgrade is not available, disable the null_blk module or prevent the device from being powered off repeatedly; consider unmounting or removing its configfs interface when it is not in use.
  • As a temporary measure, monitor system memory usage for signs of consistent growth correlated with device power cycles and plan a patch or hardware update accordingly.

Generated by OpenCVE AI on September 20, 2026 at 02:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-399
CWE-401

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: null_blk: free zones array on device power-off null_init_zoned_dev() allocates dev->zones when a zoned device is powered on, but null_del_dev() never frees it on power-off; dev->zones is only freed later in null_free_dev(), when the configfs directory is removed. If the device is powered off and then on again, null_init_zoned_dev() allocates a new array and overwrites the dev->zones pointer, leaking the previous allocation each power cycle. Free dev->zones in null_del_dev() via null_free_zoned_dev() to solve it. And calling null_free_zoned_dev() in null_free_dev() is no longer necessary because every caller already invokes null_del_dev() first: via nullb_group_drop_item() before nullb_device_release(), in the null_add_dev() error path of null_create_dev(), and in null_destroy_dev(). Remove the redundant call. And take &lock around zone_cond_store() in the two store wrappers to serialize dev->zones check-and-deref against its alloc/free, which already run under &lock. The reason there was no problem before is that only nullb_device_release() or null_exit() frees the dev->zones, which guarantees that subsequent users won't access the configfs interface.
Title null_blk: free zones array on device power-off
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:09.683Z

Reserved: 2026-09-11T19:38:34.791Z

Link: CVE-2026-90187

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:13.270

Modified: 2026-09-17T17:17:13.270

Link: CVE-2026-90187

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:15:17Z

Weaknesses