Description
In the Linux kernel, the following vulnerability has been resolved:

zram: validate deflate params

We must validate user-supplied deflate winbits before we pass it to
zlib_deflate_workspacesize(), which triggers BUG_ON() if winbits value is
outside of valid ranges.
Published: 2026-09-11
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

This vulnerability arises because the Linux kernel’s zram module fails to validate user-supplied deflate winbits before passing them to zlib_deflate_workspacesize(). When an invalid winbits value is supplied, the kernel triggers BUG_ON, causing a kernel panic and an abrupt system crash. The flaw is an unchecked input parameter that leads to a denial-of-service weakness. The associated weakness is CWE-617.

Affected Systems

All Linux kernel builds that include the zram subsystem but do not contain the patch adding this validation are affected. Because the advisory does not list specific kernel versions, any delivery of a kernel prior risk. This includes upstream stock kernels, custom builds that incorporate the upstream zram code, and any systems that still use the vulnerable code path.

Risk and Exploitability

The CVSS score of 4.4 indicates a moderate severity for a kernel panic that can be triggered via a crafted deflate winbits value, and the EPSS score of < 1% indicates a very low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local, requiring an attacker or process that can create or manipulate zram devices to supply an out-of-range winbits value. An attacker with sufficient privilege to write to the zram device could exploit the flaw to bring the system down, but the low EPSS score and lack of remote activation limit the immediate risk.

Generated by OpenCVE AI on September 15, 2026 at 19:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the commits 923578d0f0d0703c3db61ab35dc37075ae53b0bd, e23fac4ab2a5728386477b98a402a1042b21bffb, or ec7607ac4717ff521c9d8271c26293345513.
  • If an immediate kernel update is not possible, disable the zram feature or remove permission from untrusted users to create or manipulate zram devices to prevent the injection of invalid parameters.
  • Monitor system logs for PANIC messages and verify that the system remains stable after disabling or updating zram.

Generated by OpenCVE AI on September 15, 2026 at 19:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-617
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Sat, 12 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: zram: validate deflate params We must validate user-supplied deflate winbits before we pass it to zlib_deflate_workspacesize(), which triggers BUG_ON() if winbits value is outside of valid ranges.
Title zram: validate deflate params
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:46:29.953Z

Reserved: 2026-09-11T19:38:34.751Z

Link: CVE-2026-89716

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:59.123

Modified: 2026-09-11T20:19:59.123

Link: CVE-2026-89716

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:29Z

Links: CVE-2026-89716 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:30:12Z

Weaknesses