CVE-2026-89718
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/09/2026
Last modified:
21/09/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
zram: fix out-of-bounds access in writeback_store()<br />
<br />
Patch series "zram: fix stale scan bounds after reinitialization".<br />
<br />
Both writeback_store() and read_block_state() derive their table scan<br />
bounds from zram->disksize before acquiring dev_lock. If the device is<br />
reset and reinitialized with a smaller disksize between that read and lock<br />
acquisition, the bound can describe the old table while the scan operates<br />
on the new one. This can lead to out-of-bounds slot accesses.<br />
<br />
Move both bound calculations under dev_lock so each bound remains<br />
consistent with the table throughout its scan. Keep the fixes separate<br />
because the affected interfaces originate from different commits and can<br />
be backported independently.<br />
<br />
<br />
This patch (of 2):<br />
<br />
writeback_store() calculates the table scan bounds before taking dev_lock.<br />
A reset followed by reconfiguration with a smaller disksize can therefore<br />
replace zram->table while writeback_store() is waiting for the lock. Once<br />
it acquires the lock, it sees an initialized device but scans the new<br />
table using the old upper bound, resulting in an out-of-bounds access.<br />
<br />
Calculate the number of pages while holding dev_lock so the scan bound<br />
matches the table protected by the lock.


