PT-2026-93684 · Linux · Linux Kernel
CVE-2026-90043
·
Published
2026-09-16
·
Updated
2026-09-24
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the zram module where the slot lock bit position is incorrectly handled on big-endian 64-bit systems. The slot lock is a bit operation performed on the
lock word, which aliases flags and ac time as two u32 values. On big-endian 64-bit architectures, the lock bit is incorrectly placed in the ac time section instead of the flags section. When ZRAM TRACK ENTRY ACTIME is enabled, operations in mark slot accessed() or slot free() that store access time can overwrite the held lock bit, allowing another CPU to acquire the same slot lock. Conversely, an access time value with that bit set can make the slot appear permanently locked.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel