CVE-2026-89717

Summary

In the Linux kernel, the following vulnerability has been resolved:

zram: set default primary compressor in zram_destroy_comps()

Patch series "zram: fix zram issues reported by sashiko".

Sashiko drove by and reported [1] a couple of zram issues: a possible BUG_ON() in zlib code due to missing winbits range validation and one possible NULL-ptr dereference in zcomp. Both are low risk yet still worth fixing.

This patch (of 2):

zram_destroy_comps() resets all compressors and leaves them set to NULL, including the primary one, which is invalid device state, as now comp_algorithm_show()->strcmp() can be called on a NULL compressor. Set default primary compressor in zram_destroy_comps().

Affected Software

VendorProductVersion RangeStatus
LinuxLinux486fd58af7ac1098b68370b1d4d9f94a2a1c7124 < 5cec3e60e9f2d1324179df3aa91656f90095cf8faffected
LinuxLinux486fd58af7ac1098b68370b1d4d9f94a2a1c7124 < dea8f13c3dfad8b990f8ea96c997aabeebbc1d22affected
LinuxLinux486fd58af7ac1098b68370b1d4d9f94a2a1c7124 < dde75313eed0b014c437f48dd75c0308b592cbf9affected
LinuxLinux6e20720b12299595154857fa98222729f0d5823caffected
LinuxLinuxc4e5683c3031a33dc46954e99d37cbd2f706cdb6affected
LinuxLinux6.6.57 < 6.7affected
LinuxLinux6.11.4 < 6.12affected
LinuxLinux6.12affected
LinuxLinux0 < 6.12unaffected
LinuxLinux6.18.51 <= 6.18.*unaffected
LinuxLinux7.2.4 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References