Answer in brief
CVE-2026-90188 records a Unknown severity vulnerability in null_blk: free global tag_set on init error path. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=82f402fefa50f1675bf918bcd009981bd6b30ac8 <0b2faa330184340d9418ad2c627c2ae881772e33 || >=82f402fefa50f1675bf918bcd009981bd6b30ac8 <665c94554ff0d5d88caae7f40c16c8e0a3369eda || >=82f402fefa50f1675bf918bcd009981bd6b30ac8 <2882e1450fa4597811a951196e07553ea134eb31 || >=82f402fefa50f1675bf918bcd009981bd6b30ac8 <2b59484ac1e64dd78dbe8c6140891c6308085a75 || >=82f402fefa50f1675bf918bcd009981bd6b30ac8 <081cf37e8a0e00cd91d6df53172c9d928790a798 || >=82f402fefa50f1675bf918bcd009981bd6b30ac8 <5a1c5ff3a49ba93a1fd0b70537e7a0164071760d | 0b2faa330184340d9418ad2c627c2ae881772e33, 665c94554ff0d5d88caae7f40c16c8e0a3369eda, 2882e1450fa4597811a951196e07553ea134eb31, 2b59484ac1e64dd78dbe8c6140891c6308085a75, 081cf37e8a0e00cd91d6df53172c9d928790a798, 5a1c5ff3a49ba93a1fd0b70537e7a0164071760d |
| Linux/Linuxgeneric | 4.13 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: null_blk: free global tag_set on init error path If shared_tags is enabled, null_setup_tagset() allocates the global tag_set via null_init_global_tag_set(). If device creation later fails, err_dev destroys the default devices and calls unregister_blkdev(), but never frees the global tag_set. Since module init failed, null_exit() is never invoked, so the global tag_set's tags and maps are permanently leaked. Free the global tag_set in err_dev, matching null_exit() which does if (tag_set.ops) blk_mq_free_tag_set(&tag_set).
Quoted source text, attributed separately from HOL analysis.