Description
In the Linux kernel, the following vulnerability has been resolved:

zram: set default primary compressor in zram_destroy_comps()

Patch series "zram: fix zram issues reported by sashiko".

Sashiko drove by and reported [1] a couple of zram issues:
a possible BUG_ON() in zlib code due to missing winbits range
validation and one possible NULL-ptr dereference in zcomp.
Both are low risk yet still worth fixing.


This patch (of 2):

zram_destroy_comps() resets all compressors and leaves them set to NULL,
including the primary one, which is invalid device state, as now
comp_algorithm_show()->strcmp() can be called on a NULL compressor. Set
default primary compressor in zram_destroy_comps().
Published: 2026-09-11
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Kernel crash caused by null pointer dereference in zram module
Action: Apply patch
AI Analysis

Impact

The Linux kernel’s zram module contains a flaw where the routine that destroys compressors sets the primary compressor pointer to NULL. When later code attempts to compare strings on this pointer, a null pointer dereference can occur, leading to a BUG_ON in the zlib code or a kernel panic. The vulnerability is identified as CWE‑476.

Affected Systems

All Linux kernel builds that do This includes raw kernel binaries as well as distribution kernels that maintain the legacy zram_destroy_comps() logic. Any system that can load or interact with the zram module is potentially at risk.

Risk and Exploitability

The CVSS score of 4.7 indicates moderate severity. The EPSS score of less than 1% reflects a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Exploitation would likely require local or privileged as interacting with zram interfaces or unloading the module. No publicly announced tools exist; the attack vector is inferred to be local or privileged rather than remote.

Generated by OpenCVE AI on September 15, 2026 at 19:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install a kernel version that includes the zram_destroy_comps fix or apply the upstream patch series "zram: fix zram issues reported by sashiko" to set a valid primary compressor.
  • If zram functionality is not required, disable or unload the zram module to remove the vulnerable code from the running system.
  • Keep the kernel and distribution packages updated regularly to receive future security patches that may address related or new issues.

Generated by OpenCVE AI on September 15, 2026 at 19:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 21 Sep 2026 13:30:00 +0000


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: zram: set default primary compressor in zram_destroy_comps() Patch series "zram: fix zram issues reported by sashiko". Sashiko drove by and reported [1] a couple of zram issues: a possible BUG_ON() in zlib code due to missing winbits range validation and one possible NULL-ptr dereference in zcomp. Both are low risk yet still worth fixing. This patch (of 2): zram_destroy_comps() resets all compressors and leaves them set to NULL, including the primary one, which is invalid device state, as now comp_algorithm_show()->strcmp() can be called on a NULL compressor. Set default primary compressor in zram_destroy_comps().
Title zram: set default primary compressor in zram_destroy_comps()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-21T13:14:52.732Z

Reserved: 2026-09-11T19:38:34.752Z

Link: CVE-2026-89717

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:59.233

Modified: 2026-09-21T14:17:25.850

Link: CVE-2026-89717

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:30Z

Links: CVE-2026-89717 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:30:12Z

Weaknesses