Executive brief
A vulnerability was identified in the Linux kernel's zram component, which provides compressed RAM-based swap devices. Concurrent write operations to the same memory location can cause a race condition, leading to memory leaks. Over time, this could exhaust system memory, potentially causing system instability or a complete service outage.
Technical details
A race condition exists in the zram driver (drivers/block/zram/zram_drv.c) due to improper synchronization during slot write operations. The vulnerability occurs because the kernel frees the existing memory handle (zs_free) before acquiring the lock for the new write operation. In a multi-core environment, parallel writes to the same zram index can result in leaked zsmalloc handles if one CPU overwrites the handle set by another before the previous handle is properly tracked or freed. This is classified as a Concurrent Execution using Shared Resource with Improper Synchronization (CWE-362). The fix involves moving the zram_free_page call inside the same slot lock scope as the zram_set_handle operation. Patches are available in the stable Linux kernel tree.
Affected products
- Linux Linux Kernel 6.14 to 6.16.9
Timeline
- 2025-09-09: patched: Initial patch authored by Sergey Senozhatsky
- 2025-10-04: disclosed: CVE published