Impact
This vulnerability arises because the Linux kernel’s zram module fails to validate user-supplied deflate winbits before passing them to zlib_deflate_workspacesize(). When an invalid winbits value is supplied, the kernel triggers BUG_ON, causing a kernel panic and an abrupt system crash. The flaw is an unchecked input parameter that leads to a denial-of-service weakness. The associated weakness is CWE-617.
Affected Systems
All Linux kernel builds that include the zram subsystem but do not contain the patch adding this validation are affected. Because the advisory does not list specific kernel versions, any delivery of a kernel prior risk. This includes upstream stock kernels, custom builds that incorporate the upstream zram code, and any systems that still use the vulnerable code path.
Risk and Exploitability
The CVSS score of 4.4 indicates a moderate severity for a kernel panic that can be triggered via a crafted deflate winbits value, and the EPSS score of < 1% indicates a very low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local, requiring an attacker or process that can create or manipulate zram devices to supply an out-of-range winbits value. An attacker with sufficient privilege to write to the zram device could exploit the flaw to bring the system down, but the low EPSS score and lack of remote activation limit the immediate risk.
OpenCVE Enrichment