Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-89718

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
11/09/2026
Última modificación:
21/09/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> zram: fix out-of-bounds access in writeback_store()<br /> <br /> Patch series "zram: fix stale scan bounds after reinitialization".<br /> <br /> Both writeback_store() and read_block_state() derive their table scan<br /> bounds from zram-&gt;disksize before acquiring dev_lock. If the device is<br /> reset and reinitialized with a smaller disksize between that read and lock<br /> acquisition, the bound can describe the old table while the scan operates<br /> on the new one. This can lead to out-of-bounds slot accesses.<br /> <br /> Move both bound calculations under dev_lock so each bound remains<br /> consistent with the table throughout its scan. Keep the fixes separate<br /> because the affected interfaces originate from different commits and can<br /> be backported independently.<br /> <br /> <br /> This patch (of 2):<br /> <br /> writeback_store() calculates the table scan bounds before taking dev_lock.<br /> A reset followed by reconfiguration with a smaller disksize can therefore<br /> replace zram-&gt;table while writeback_store() is waiting for the lock. Once<br /> it acquires the lock, it sees an initialized device but scans the new<br /> table using the old upper bound, resulting in an out-of-bounds access.<br /> <br /> Calculate the number of pages while holding dev_lock so the scan bound<br /> matches the table protected by the lock.

Impacto