Description
In the Linux kernel, the following vulnerability has been resolved:

null_blk: use DEFINE_MUTEX for the file-scope mutex

In null_init(), mutex_init(&lock) currently happens after
configfs_register_subsystem(), which exposes the nullb subsystem to
userspace. A racing mkdir() into /sys/kernel/config/nullb/ can reach
null_find_dev_by_name() -> mutex_lock(&lock) before the mutex is
initialized, trigger warning:

[ 123.137788] DEBUG_LOCKS_WARN_ON(lock->magic != lock)
[ 123.137796] WARNING: kernel/locking/mutex.c:159 at mutex_lock+0x171/0x1c0, CPU#13: mkdir/1301
[ 123.140090] Modules linked in: null_blk(+) nft_fib_inet nft_fib_ipv4
......
[ 123.154926] Call Trace:
[ 123.155172] <TASK>
[ 123.155419] ? __pfx_mutex_lock+0x10/0x10
[ 123.156181] ? __pfx__raw_spin_lock+0x10/0x10
[ 123.156571] nullb_group_make_group+0x20/0x100 [null_blk]
[ 123.157011] configfs_mkdir+0x47b/0xc70
[ 123.157337] ? __pfx_configfs_mkdir+0x10/0x10
[ 123.157719] ? may_create_dentry+0x242/0x2e0
[ 123.158061] vfs_mkdir+0x2a9/0x6c0
[ 123.158352] filename_mkdirat+0x3dc/0x500
[ 123.158710] ? __pfx_filename_mkdirat+0x10/0x10
[ 123.159070] ? strncpy_from_user+0x3a/0x1d0
[ 123.159413] __x64_sys_mkdir+0x6b/0x90
[ 123.159760] do_syscall_64+0xea/0x600

Replace the runtime mutex_init(&lock) with a static DEFINE_MUTEX(lock)
declaration to fix this issue.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Race condition leading to the use of an uninitialized mutex in the Linux kernel null_blk module, which can cause kernel warnings and potentially instability or denial of service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from initializing a mutex after the subsystem is exposed to userspace. A race condition allows a user to perform a mkdir operation on the null_blk configuration directory before the mutex is initialized, causing the kernel to lock a mutex that has not yet been set up. This can trigger kernel warnings and, if not handled correctly, could lead to kernel instability or denial of service. The weakness relates to improper initialization of synchronization primitives and a concurrent access race.

Affected Systems

The flaw exists in the Linux kernel as part of the null_blk module. All kernel builds that include null_blk and expose the /sys/kernel/config/nullb/ interface are affected. No specific version range is supplied, so any kernel containing the unpatched null_blk implementation is potentially vulnerable.

Risk and Exploitability

The high impact of breaking kernel synchronization is offset by a low exploitation probability—the EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local, requiring the ability to create a directory in the kernel’s configfs interface, typically a privileged or root operation. While remote exploitation is not indicated, an attacker who can gain local or root access could trigger the race, leading to a denial‑of‑service condition. The overall risk is moderate: a precise patch or disabling the module mitigates the issue entirely.

Generated by OpenCVE AI on September 20, 2026 at 02:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version where null_blk uses DEFINE_MUTEX for the mutex declaration.
  • If a kernel update is not immediately possible, compile the kernel with a patched copy of null_blk or recompile the module with the static mutex initializer.
  • If the null_blk subsystem is not required, disable or unload the null_blk module and remove the /sys/kernel/config/nullb/ configuration node.

Generated by OpenCVE AI on September 20, 2026 at 02:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-367
CWE-665

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: null_blk: use DEFINE_MUTEX for the file-scope mutex In null_init(), mutex_init(&lock) currently happens after configfs_register_subsystem(), which exposes the nullb subsystem to userspace. A racing mkdir() into /sys/kernel/config/nullb/ can reach null_find_dev_by_name() -> mutex_lock(&lock) before the mutex is initialized, trigger warning: [ 123.137788] DEBUG_LOCKS_WARN_ON(lock->magic != lock) [ 123.137796] WARNING: kernel/locking/mutex.c:159 at mutex_lock+0x171/0x1c0, CPU#13: mkdir/1301 [ 123.140090] Modules linked in: null_blk(+) nft_fib_inet nft_fib_ipv4 ...... [ 123.154926] Call Trace: [ 123.155172] <TASK> [ 123.155419] ? __pfx_mutex_lock+0x10/0x10 [ 123.156181] ? __pfx__raw_spin_lock+0x10/0x10 [ 123.156571] nullb_group_make_group+0x20/0x100 [null_blk] [ 123.157011] configfs_mkdir+0x47b/0xc70 [ 123.157337] ? __pfx_configfs_mkdir+0x10/0x10 [ 123.157719] ? may_create_dentry+0x242/0x2e0 [ 123.158061] vfs_mkdir+0x2a9/0x6c0 [ 123.158352] filename_mkdirat+0x3dc/0x500 [ 123.158710] ? __pfx_filename_mkdirat+0x10/0x10 [ 123.159070] ? strncpy_from_user+0x3a/0x1d0 [ 123.159413] __x64_sys_mkdir+0x6b/0x90 [ 123.159760] do_syscall_64+0xea/0x600 Replace the runtime mutex_init(&lock) with a static DEFINE_MUTEX(lock) declaration to fix this issue.
Title null_blk: use DEFINE_MUTEX for the file-scope mutex
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:11.654Z

Reserved: 2026-09-11T19:38:34.792Z

Link: CVE-2026-90190

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:13.670

Modified: 2026-09-17T17:17:13.670

Link: CVE-2026-90190

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:15:17Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition

  • CWE-665

    Improper Initialization