CVE-2026-89718

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/09/2026
Last modified:
21/09/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> zram: fix out-of-bounds access in writeback_store()<br /> <br /> Patch series "zram: fix stale scan bounds after reinitialization".<br /> <br /> Both writeback_store() and read_block_state() derive their table scan<br /> bounds from zram-&gt;disksize before acquiring dev_lock. If the device is<br /> reset and reinitialized with a smaller disksize between that read and lock<br /> acquisition, the bound can describe the old table while the scan operates<br /> on the new one. This can lead to out-of-bounds slot accesses.<br /> <br /> Move both bound calculations under dev_lock so each bound remains<br /> consistent with the table throughout its scan. Keep the fixes separate<br /> because the affected interfaces originate from different commits and can<br /> be backported independently.<br /> <br /> <br /> This patch (of 2):<br /> <br /> writeback_store() calculates the table scan bounds before taking dev_lock.<br /> A reset followed by reconfiguration with a smaller disksize can therefore<br /> replace zram-&gt;table while writeback_store() is waiting for the lock. Once<br /> it acquires the lock, it sees an initialized device but scans the new<br /> table using the old upper bound, resulting in an out-of-bounds access.<br /> <br /> Calculate the number of pages while holding dev_lock so the scan bound<br /> matches the table protected by the lock.

Impact