Junglewise Threat Intelligence

CVE-2026-46089: Linux kernel zram infinite hang in partial discard requests

CVE-2026-46089 · Severity: info · CVSS 4 · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's zram driver can cause certain system processes to hang indefinitely. zram is a component used to create compressed RAM-based swap devices to improve system performance. When a specific type of storage command (a partial discard) is sent to a zram device, the system fails to signal that the task is finished, leading to a permanent wait state that can disrupt system operations or management tools.

Technical details

A flaw exists in the zram_bio_discard function within drivers/block/zram/zram_drv.c of the Linux kernel. When a partial discard request is received (where the request size is smaller than the page size), the driver returns immediately without calling bio_endio(). This causes the block layer to wait indefinitely for a completion signal that never arrives, leading to a permanent hang of the blkdiscard utility or any process using submit_bio_wait(). The fix involves ensuring the code paths for partial discards correctly jump to the end_bio label to execute bio_endio(). Patches have been merged into multiple stable branches of the Linux kernel.

Affected products

  • Linux Linux kernel All versions prior to the May 2026 patches

Timeline

  • 2026-03-31: disclosed: Vulnerability reported and patch submitted by Sergey Senozhatsky
  • 2026-05-17: patched: Patches committed to stable kernel trees
  • 2026-05-27: advisory: CVE-2026-46089 published

References