Critical Alert 1 Active Exploit Detected Today

CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

← Back to CVE List

CVE-2026-90187NVD

Vulnerability Summary

In the Linux kernel, the following vulnerability has been resolved:

null_blk: free zones array on device power-off

null_init_zoned_dev() allocates dev->zones when a zoned device is powered
on, but null_del_dev() never frees it on power-off; dev->zones is only
freed later in null_free_dev(), when the configfs directory is removed. If
the device is powered off and then on again, null_init_zoned_dev()
allocates a new array and overwrites the dev->zones pointer, leaking the
previous allocation each power cycle.

Free dev->zones in null_del_dev() via null_free_zoned_dev() to solve it.
And calling null_free_zoned_dev() in null_free_dev() is no longer necessary
because every caller already invokes null_del_dev() first: via
nullb_group_drop_item() before nullb_device_release(), in the
null_add_dev() error path of null_create_dev(), and in null_destroy_dev().
Remove the redundant call.

And take &lock around zone_cond_store() in the two store wrappers to
serialize dev->zones check-and-deref against its alloc/free, which already
run under &lock. The reason there was no problem before is that only
nullb_device_release() or null_exit() frees the dev->zones, which
guarantees that subsequent users won't access the configfs interface.
Severity Level
UNKNOWN
Published Date
Sep 17, 2026
Last Modified
Sep 17, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.20%Probability
Root Weakness (CWE)
N/A

Affected & Patched Versions

Affected Versions
  • Linux Linux >= ca4b2a011948fae4e4d31490107db4926385a983 and < 056be41932c95aabdb3c2967d1ef4978f17a0225
  • Linux Linux >= ca4b2a011948fae4e4d31490107db4926385a983 and < b2437d37fcc31fce8a5da1cc1739e284814d2491
  • Linux Linux >= ca4b2a011948fae4e4d31490107db4926385a983 and < 0a3afab87124171022fb3579502fa38ef5b311c9
  • Linux Linux >= ca4b2a011948fae4e4d31490107db4926385a983 and < 2a6357a9b935a34f5508618fee8a7fffbf7722a8
  • Linux Linux >= 4.19
Patched Versions
  • Linux Linux 056be41932c95aabdb3c2967d1ef4978f17a0225
  • Linux Linux b2437d37fcc31fce8a5da1cc1739e284814d2491
  • Linux Linux 0a3afab87124171022fb3579502fa38ef5b311c9
  • Linux Linux 2a6357a9b935a34f5508618fee8a7fffbf7722a8
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.