Description
In the Linux kernel, the following vulnerability has been resolved:

zram: fix out-of-bounds access in writeback_store()

Patch series "zram: fix stale scan bounds after reinitialization".

Both writeback_store() and read_block_state() derive their table scan
bounds from zram->disksize before acquiring dev_lock. If the device is
reset and reinitialized with a smaller disksize between that read and lock
acquisition, the bound can describe the old table while the scan operates
on the new one. This can lead to out-of-bounds slot accesses.

Move both bound calculations under dev_lock so each bound remains
consistent with the table throughout its scan. Keep the fixes separate
because the affected interfaces originate from different commits and can
be backported independently.


This patch (of 2):

writeback_store() calculates the table scan bounds before taking dev_lock.
A reset followed by reconfiguration with a smaller disksize can therefore
replace zram->table while writeback_store() is waiting for the lock. Once
it acquires the lock, it sees an initialized device but scans the new
table using the old upper bound, resulting in an out-of-bounds access.

Calculate the number of pages while holding dev_lock so the scan bound
matches the table protected by the lock.
Published: 2026-09-11
Score: 4.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Kernel out-of-bounds memory access
Action: Apply patch
AI Analysis

Impact

The vulnerability occurs in the Linux kernel’s zram module when writeback_store() and read_block_state() calculate table scan bounds from zram->disksize before acquiring dev_lock. If a device disksize between that calculation and lock acquisition, the scan operates on a table that no longer matches the bounds, leading to out‑of‑bounds slot accesses. This out‑of‑bounds array access is a CWE‑131 vulnerability and can result in memory corruption, crashing the kernel or corrupting kernel data structures. Based on the description, the likely attack vector requires local interaction with the zram device, involving a reset or in progress.

Affected Systems

All Linux kernel builds that include the zram module and have not applied the zram: fix stale scan bounds after reinitialization patch are affected; specific kernel versions are not listed, so any unpatched kernel that exposes a zram device is at risk.

Risk and Exploitability

The CVSS score of 4.1 classifies this as low severity, reflecting that the fault appears to require local interaction with the zram device (inferred from the description) and is not publicly exploitable at this time. The EPSS score of less than 1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in KEV. Successful exploitation would involve the period between bound calculation and lock acquisition, where the kernel performs a scan using an outdated bound. Because corruption occurs in kernel space, it could lead to a crash or data corruption, though privilege escalation is not explicitly described.

Generated by OpenCVE AI on September 15, 2026 at 19:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the 'zram: fix stale scan bounds after reinitialization' patch series
  • If a kernel update is not possible, disable the zram module on systems that do not require it to reduce the attack surface
  • Avoid performing a zram device reset or size change while zram operations are in progress; modify scripts or applications to enforce exclusive access or to perform reinitialization only after all operations have completed

Generated by OpenCVE AI on September 15, 2026 at 19:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 21 Sep 2026 13:30:00 +0000


Sat, 12 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-131
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Sat, 12 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: zram: fix out-of-bounds access in writeback_store() Patch series "zram: fix stale scan bounds after reinitialization". Both writeback_store() and read_block_state() derive their table scan bounds from zram->disksize before acquiring dev_lock. If the device is reset and reinitialized with a smaller disksize between that read and lock acquisition, the bound can describe the old table while the scan operates on the new one. This can lead to out-of-bounds slot accesses. Move both bound calculations under dev_lock so each bound remains consistent with the table throughout its scan. Keep the fixes separate because the affected interfaces originate from different commits and can be backported independently. This patch (of 2): writeback_store() calculates the table scan bounds before taking dev_lock. A reset followed by reconfiguration with a smaller disksize can therefore replace zram->table while writeback_store() is waiting for the lock. Once it acquires the lock, it sees an initialized device but scans the new table using the old upper bound, resulting in an out-of-bounds access. Calculate the number of pages while holding dev_lock so the scan bound matches the table protected by the lock.
Title zram: fix out-of-bounds access in writeback_store()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-21T13:14:53.779Z

Reserved: 2026-09-11T19:38:34.752Z

Link: CVE-2026-89718

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:59.377

Modified: 2026-09-21T14:17:25.967

Link: CVE-2026-89718

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:31Z

Links: CVE-2026-89718 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:30:12Z

Weaknesses
  • CWE-131

    Incorrect Calculation of Buffer Size