Impact
The vulnerability occurs in the Linux kernel’s zram module when writeback_store() and read_block_state() calculate table scan bounds from zram->disksize before acquiring dev_lock. If a device disksize between that calculation and lock acquisition, the scan operates on a table that no longer matches the bounds, leading to out‑of‑bounds slot accesses. This out‑of‑bounds array access is a CWE‑131 vulnerability and can result in memory corruption, crashing the kernel or corrupting kernel data structures. Based on the description, the likely attack vector requires local interaction with the zram device, involving a reset or in progress.
Affected Systems
All Linux kernel builds that include the zram module and have not applied the zram: fix stale scan bounds after reinitialization patch are affected; specific kernel versions are not listed, so any unpatched kernel that exposes a zram device is at risk.
Risk and Exploitability
The CVSS score of 4.1 classifies this as low severity, reflecting that the fault appears to require local interaction with the zram device (inferred from the description) and is not publicly exploitable at this time. The EPSS score of less than 1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in KEV. Successful exploitation would involve the period between bound calculation and lock acquisition, where the kernel performs a scan using an outdated bound. Because corruption occurs in kernel space, it could lead to a crash or data corruption, though privilege escalation is not explicitly described.
OpenCVE Enrichment
Debian DSA