PT-2026-90433 · Linux · Linux

CVE-2026-89717

·

Published

2026-09-11

·

Updated

2026-09-11

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
zram: set default primary compressor in zram destroy comps()
Patch series "zram: fix zram issues reported by sashiko".
Sashiko drove by and reported [1] a couple of zram issues: a possible BUG ON() in zlib code due to missing winbits range validation and one possible NULL-ptr dereference in zcomp. Both are low risk yet still worth fixing.
This patch (of 2):
zram destroy comps() resets all compressors and leaves them set to NULL, including the primary one, which is invalid device state, as now comp algorithm show()->strcmp() can be called on a NULL compressor. Set default primary compressor in zram destroy comps().
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-89717

Affected Products

Linux