CVE-2026-89717
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/09/2026
Last modified:
21/09/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
zram: set default primary compressor in zram_destroy_comps()<br />
<br />
Patch series "zram: fix zram issues reported by sashiko".<br />
<br />
Sashiko drove by and reported [1] a couple of zram issues:<br />
a possible BUG_ON() in zlib code due to missing winbits range<br />
validation and one possible NULL-ptr dereference in zcomp.<br />
Both are low risk yet still worth fixing.<br />
<br />
<br />
This patch (of 2):<br />
<br />
zram_destroy_comps() resets all compressors and leaves them set to NULL,<br />
including the primary one, which is invalid device state, as now<br />
comp_algorithm_show()->strcmp() can be called on a NULL compressor. Set<br />
default primary compressor in zram_destroy_comps().


