Junglewise Threat Intelligence

CVE-2026-90186: Linux kernel null_blk queue resize denial of service in shared tag set

CVE-2026-90186 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's null_blk storage module contains a flaw that allows a local user to crash the system via a null pointer dereference when attempting to resize per-device queues on devices configured with shared tag sets. This is a denial-of-service issue affecting systems using this block device driver for testing or development.

Technical details

The vulnerability exists in the null_blk kernel module when the shared_tags feature is enabled. When a user attempts to resize submit_queues or poll_queues via configfs on a device bound to the global tag_set, the code calls blk_mq_update_nr_hw_queues() which shrinks the hardware context array but leaves stale pointers in the queue map. The null_map_queues() function continues to reference these NULL hardware contexts, leading to a NULL pointer dereference in blk_mq_map_swqueue() when it tries to access hctx->cpumask. The fix rejects per-device queue resizing with -EINVAL when the device is bound to the global tag set, since such resizing is meaningless in this configuration. Local administrative access (via configfs) is required to trigger this vulnerability.

Affected products

  • Linux Linux kernel 7.2.0-rc2 and likely others

Timeline

  • 2026-09-17: disclosed

Related threats