Description
In the Linux kernel, the following vulnerability has been resolved:

zram: fix slot lock bit position on big-endian 64-bit

The slot lock is a bit operation on the whole __lock word, which flags and
ac_time alias as two u32s. On little-endian the lock bit lands in the
position ZRAM_ENTRY_LOCK reserves in flags, so the aliasing works out. On
64-bit big-endian it lands in ac_time instead: with
ZRAM_TRACK_ENTRY_ACTIME enabled, storing the access time from
mark_slot_accessed() or slot_free() wipes out the held lock bit, letting
another CPU take the same slot lock; an access time value with that bit
set makes the slot look locked forever.

Shift the lock bit into the flags half of the word on big-endian 64-bit.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Data Corruption / Denial of Service
Action: Patch ASAP
AI Analysis

Impact

The defect arises from the misplacement of the slot‑lock bit in the zram subsystem on big‑endian 64‑bit CPUs. Because the bit lands in the access‑time part of the word instead of the flags field, writes that record the slot’s last‑access time overwrite the lock flag when the tracking feature is enabled. A thread that has already acquired the slot can therefore be released prematurely, allowing another CPU to access the same compressed‑ram entry concurrently. This race results in corruption of the data stored in the slot or in a failure of a process that relies on zram, and it maps to CWE‑362, a concurrent‑execution race condition. The improper lock handling also permits the lock state to be permanently lost, effectively disabling zram in that slot and leading to a denial of service.

Affected Systems

Linux kernel implementations that use the zram compressed‑ram device on 64‑bit big‑endian hardware and have the ZRAM_TRACK_ENTRY_ACTIME configuration enabled or compiled as default. Any kernel build prior to the commit linked above is potentially affected. No other vendors or product families are known to be impacted beyond the generic Linux kernel.

Risk and Exploitability

The flaw carries a CVSS score of 7.8 and an EPSS score of less than 1 %, indicating a high‑impact but low‑likelihood scenario in the wild. The KEV list does not contain this issue, suggesting no publicly known exploits. Attackers must be able to run code on the host with access to the zram device, so the vector is local. A successful exploitation would let a local process corrupt or crash other processes that use the same zram backing, but remote attack is unlikely without local privileges.

Generated by OpenCVE AI on September 18, 2026 at 05:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a version that incorporates the commit which corrects the slot‑lock bit position.
  • Temporarily disable the ZRAM_TRACK_ENTRY_ACTIME feature by setting the corresponding kernel configuration option off until a patched kernel is available.
  • If a kernel update cannot be performed immediately, remove or unload the zram module from the initramfs or runtime configuration to prevent usage of the vulnerable implementation.

Generated by OpenCVE AI on September 18, 2026 at 05:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: zram: fix slot lock bit position on big-endian 64-bit The slot lock is a bit operation on the whole __lock word, which flags and ac_time alias as two u32s. On little-endian the lock bit lands in the position ZRAM_ENTRY_LOCK reserves in flags, so the aliasing works out. On 64-bit big-endian it lands in ac_time instead: with ZRAM_TRACK_ENTRY_ACTIME enabled, storing the access time from mark_slot_accessed() or slot_free() wipes out the held lock bit, letting another CPU take the same slot lock; an access time value with that bit set makes the slot look locked forever. Shift the lock bit into the flags half of the word on big-endian 64-bit.
Title zram: fix slot lock bit position on big-endian 64-bit
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:41:56.643Z

Reserved: 2026-09-11T19:38:34.783Z

Link: CVE-2026-90043

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:17.557

Modified: 2026-09-16T15:18:26.990

Link: CVE-2026-90043

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:30:04Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')