CVE-2026-90188 PUBLISHED

null_blk: free global tag_set on init error path

Assigner: Linux
Reserved: 11.09.2026 Published: 17.09.2026 Updated: 17.09.2026

In the Linux kernel, the following vulnerability has been resolved:

null_blk: free global tag_set on init error path

If shared_tags is enabled, null_setup_tagset() allocates the global tag_set via null_init_global_tag_set(). If device creation later fails, err_dev destroys the default devices and calls unregister_blkdev(), but never frees the global tag_set. Since module init failed, null_exit() is never invoked, so the global tag_set's tags and maps are permanently leaked.

Free the global tag_set in err_dev, matching null_exit() which does if (tag_set.ops) blk_mq_free_tag_set(&tag_set).

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 82f402fefa50f1675bf918bcd009981bd6b30ac8 to 0b2faa330184340d9418ad2c627c2ae881772e33 (excl.)
  • affected from 82f402fefa50f1675bf918bcd009981bd6b30ac8 to 665c94554ff0d5d88caae7f40c16c8e0a3369eda (excl.)
  • affected from 82f402fefa50f1675bf918bcd009981bd6b30ac8 to 2882e1450fa4597811a951196e07553ea134eb31 (excl.)
  • affected from 82f402fefa50f1675bf918bcd009981bd6b30ac8 to 2b59484ac1e64dd78dbe8c6140891c6308085a75 (excl.)
  • affected from 82f402fefa50f1675bf918bcd009981bd6b30ac8 to 081cf37e8a0e00cd91d6df53172c9d928790a798 (excl.)
  • affected from 82f402fefa50f1675bf918bcd009981bd6b30ac8 to 5a1c5ff3a49ba93a1fd0b70537e7a0164071760d (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 4.13 is affected
  • unaffected from 0 to 4.13 (excl.)
  • unaffected from 6.1.188 to 6.1.* (incl.)
  • unaffected from 6.6.157 to 6.6.* (incl.)
  • unaffected from 6.12.110 to 6.12.* (incl.)
  • unaffected from 6.18.52 to 6.18.* (incl.)
  • unaffected from 7.2.6 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References