Impact
The vulnerability arises from initializing a mutex after the subsystem is exposed to userspace. A race condition allows a user to perform a mkdir operation on the null_blk configuration directory before the mutex is initialized, causing the kernel to lock a mutex that has not yet been set up. This can trigger kernel warnings and, if not handled correctly, could lead to kernel instability or denial of service. The weakness relates to improper initialization of synchronization primitives and a concurrent access race.
Affected Systems
The flaw exists in the Linux kernel as part of the null_blk module. All kernel builds that include null_blk and expose the /sys/kernel/config/nullb/ interface are affected. No specific version range is supplied, so any kernel containing the unpatched null_blk implementation is potentially vulnerable.
Risk and Exploitability
The high impact of breaking kernel synchronization is offset by a low exploitation probability—the EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local, requiring the ability to create a directory in the kernel’s configfs interface, typically a privileged or root operation. While remote exploitation is not indicated, an attacker who can gain local or root access could trigger the race, leading to a denial‑of‑service condition. The overall risk is moderate: a precise patch or disabling the module mitigates the issue entirely.
OpenCVE Enrichment
Debian DLA
Debian DSA