Description
In the Linux kernel, the following vulnerability has been resolved:

null_blk: free global tag_set on init error path

If shared_tags is enabled, null_setup_tagset() allocates the global tag_set
via null_init_global_tag_set(). If device creation later fails, err_dev
destroys the default devices and calls unregister_blkdev(), but never frees
the global tag_set. Since module init failed, null_exit() is never invoked,
so the global tag_set's tags and maps are permanently leaked.

Free the global tag_set in err_dev, matching null_exit() which does
if (tag_set.ops) blk_mq_free_tag_set(&tag_set).
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via persistent memory leak
Action: Patch
AI Analysis

Impact

In the Linux kernel the null_blk module can leak memory and kernel resources when its initialization fails. During boot the module allocates a global tag_set for block I/O tagging. If the subsequent device creation fails, the cleanup routine improperly omits freeing this global tag_set, resulting in a permanent memory leak. The leaked tag_set occupies kernel memory and its internal maps, which can grow unbounded over time and degrade system performance or lead to a complete memory exhaustion, effectively causing a denial of service.

Affected Systems

The vulnerability is present in the Linux kernel, affecting all distributions that ship a kernel module named null_blk. No specific kernel version range is listed in the advisory, so kernels prior to the patch referenced in the advisory are considered affected.

Risk and Exploitability

The EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation in the wild. The exploitation requires code executed in kernel mode, typically as a local privileged attacker or a malicious module loader. The primary risk is a local denial of service; remotely-triggered exploitation would be limited by the need for kernel module loading privileges.

Generated by OpenCVE AI on September 20, 2026 at 02:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to a kernel version that includes the null_blk tag_set cleanup fix
  • If updating is not feasible, disable the NULL_BLK block I/O tag module entirely through kernel module configuration or modprobe blacklist
  • Verify that any custom module initialization code properly frees resources on error paths, or replace the null_blk module with a maintained alternative

Generated by OpenCVE AI on September 20, 2026 at 02:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: null_blk: free global tag_set on init error path If shared_tags is enabled, null_setup_tagset() allocates the global tag_set via null_init_global_tag_set(). If device creation later fails, err_dev destroys the default devices and calls unregister_blkdev(), but never frees the global tag_set. Since module init failed, null_exit() is never invoked, so the global tag_set's tags and maps are permanently leaked. Free the global tag_set in err_dev, matching null_exit() which does if (tag_set.ops) blk_mq_free_tag_set(&tag_set).
Title null_blk: free global tag_set on init error path
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:10.349Z

Reserved: 2026-09-11T19:38:34.791Z

Link: CVE-2026-90188

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:13.397

Modified: 2026-09-17T17:17:13.397

Link: CVE-2026-90188

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:15:17Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption