Junglewise Threat Intelligence

CVE-2026-89718: Linux kernel zram out-of-bounds access in writeback_store

CVE-2026-89718 · Severity: info · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

zram is a memory compression module in the Linux kernel used to reduce RAM usage. A race condition in the writeback function allows an attacker with local access to trigger out-of-bounds memory reads by resizing the compression device while the writeback operation is running. This could lead to kernel crashes or information disclosure.

Technical details

A time-of-check-to-time-of-use (TOCTOU) race condition exists in the zram writeback_store() function. The function calculates table scan bounds (nr_pages and hi) from zram->disksize before acquiring the dev_lock. If the device is reset and reinitialized with a smaller disksize between the bound calculation and lock acquisition, the zram->table is replaced while writeback_store() is waiting. When the function acquires the lock, it scans the new (smaller) table using the old (larger) bounds, resulting in out-of-bounds slot access. The fix moves the bound calculations under the lock to ensure consistency. Local access to the /sys interface for writeback control is required to trigger this race.

Affected products

  • Linux Linux kernel all versions with zram (writeback feature introduced in commit a939888ec38b)

Timeline

  • 2026-09-11: disclosed: CVE-2026-89718 published
  • 2026-08-04: patched: Fix committed by Longlong Xia
  • 2026-09-07: other: Patch merged to stable tree

References

Related threats