Executive brief
zram is a memory compression module in the Linux kernel used to reduce RAM usage. A race condition in the writeback function allows an attacker with local access to trigger out-of-bounds memory reads by resizing the compression device while the writeback operation is running. This could lead to kernel crashes or information disclosure.
Technical details
A time-of-check-to-time-of-use (TOCTOU) race condition exists in the zram writeback_store() function. The function calculates table scan bounds (nr_pages and hi) from zram->disksize before acquiring the dev_lock. If the device is reset and reinitialized with a smaller disksize between the bound calculation and lock acquisition, the zram->table is replaced while writeback_store() is waiting. When the function acquires the lock, it scans the new (smaller) table using the old (larger) bounds, resulting in out-of-bounds slot access. The fix moves the bound calculations under the lock to ensure consistency. Local access to the /sys interface for writeback control is required to trigger this race.
Affected products
- Linux Linux kernel all versions with zram (writeback feature introduced in commit a939888ec38b)
Timeline
- 2026-09-11: disclosed: CVE-2026-89718 published
- 2026-08-04: patched: Fix committed by Longlong Xia
- 2026-09-07: other: Patch merged to stable tree