Impact
The Linux kernel’s zram module contains a flaw where the routine that destroys compressors sets the primary compressor pointer to NULL. When later code attempts to compare strings on this pointer, a null pointer dereference can occur, leading to a BUG_ON in the zlib code or a kernel panic. The vulnerability is identified as CWE‑476.
Affected Systems
All Linux kernel builds that do This includes raw kernel binaries as well as distribution kernels that maintain the legacy zram_destroy_comps() logic. Any system that can load or interact with the zram module is potentially at risk.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate severity. The EPSS score of less than 1% reflects a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Exploitation would likely require local or privileged as interacting with zram interfaces or unloading the module. No publicly announced tools exist; the attack vector is inferred to be local or privileged rather than remote.
OpenCVE Enrichment
Debian DSA