Impact
The defect arises from the misplacement of the slot‑lock bit in the zram subsystem on big‑endian 64‑bit CPUs. Because the bit lands in the access‑time part of the word instead of the flags field, writes that record the slot’s last‑access time overwrite the lock flag when the tracking feature is enabled. A thread that has already acquired the slot can therefore be released prematurely, allowing another CPU to access the same compressed‑ram entry concurrently. This race results in corruption of the data stored in the slot or in a failure of a process that relies on zram, and it maps to CWE‑362, a concurrent‑execution race condition. The improper lock handling also permits the lock state to be permanently lost, effectively disabling zram in that slot and leading to a denial of service.
Affected Systems
Linux kernel implementations that use the zram compressed‑ram device on 64‑bit big‑endian hardware and have the ZRAM_TRACK_ENTRY_ACTIME configuration enabled or compiled as default. Any kernel build prior to the commit linked above is potentially affected. No other vendors or product families are known to be impacted beyond the generic Linux kernel.
Risk and Exploitability
The flaw carries a CVSS score of 7.8 and an EPSS score of less than 1 %, indicating a high‑impact but low‑likelihood scenario in the wild. The KEV list does not contain this issue, suggesting no publicly known exploits. Attackers must be able to run code on the host with access to the zram device, so the vector is local. A successful exploitation would let a local process corrupt or crash other processes that use the same zram backing, but remote attack is unlikely without local privileges.
OpenCVE Enrichment