CVE-2026-89717

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/09/2026
Last modified:
21/09/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> zram: set default primary compressor in zram_destroy_comps()<br /> <br /> Patch series "zram: fix zram issues reported by sashiko".<br /> <br /> Sashiko drove by and reported [1] a couple of zram issues:<br /> a possible BUG_ON() in zlib code due to missing winbits range<br /> validation and one possible NULL-ptr dereference in zcomp.<br /> Both are low risk yet still worth fixing.<br /> <br /> <br /> This patch (of 2):<br /> <br /> zram_destroy_comps() resets all compressors and leaves them set to NULL,<br /> including the primary one, which is invalid device state, as now<br /> comp_algorithm_show()-&gt;strcmp() can be called on a NULL compressor. Set<br /> default primary compressor in zram_destroy_comps().

Impact