PT-2026-93684 · Linux · Linux Kernel

CVE-2026-90043

·

Published

2026-09-16

·

Updated

2026-09-24

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the zram module where the slot lock bit position is incorrectly handled on big-endian 64-bit systems. The slot lock is a bit operation performed on the lock word, which aliases flags and ac time as two u32 values. On big-endian 64-bit architectures, the lock bit is incorrectly placed in the ac time section instead of the flags section. When ZRAM TRACK ENTRY ACTIME is enabled, operations in mark slot accessed() or slot free() that store access time can overwrite the held lock bit, allowing another CPU to acquire the same slot lock. Conversely, an access time value with that bit set can make the slot appear permanently locked.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-90043
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel