Impact
The null_blk kernel module contains a race condition in which the configfs subsystem is registered before the block device major number is initialized. A concurrent mkdir() and power‑on operation from userspace can trigger null_add_dev() when the major number is still zero, causing a WARN_ON in __add_disk and aborting device creation. On module unload, the error path frees user‑created null_blk devices while their sysfs entries remain accessible, enabling a use‑after‑free when a user subsequently accesses those entries, potentially corrupting kernel memory.
Affected Systems
The flaw exists in all Linux kernel builds that include the null_blk module as a loadable module. Any system that loads this module, whether at boot or on demand, is susceptible when userspace performs configfs operations concurrently with device power‑on or during module removal while devices remain active.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating low current exploitation probability. However, because the flaw can lead to kernel memory corruption via a use‑after‑free, its potential impact is high. Privileged users who can create sysfs directories for null_blk and race module initialization meet realistic conditions in multi‑user environments, giving the vulnerability a moderate to high severity that warrants prompt remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA