← All Advisories

CVE-2026-89719

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-89719

Key Details

CVECVE-2026-89719
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

zram: fix out-of-bounds access in read_block_state()

read_block_state() calculates nr_pages before taking dev_lock. If the

device is reset and reinitialized with a smaller disksize before lock

acquisition, nr_pages still describes the old table. The subsequent loop

can then call slot_lock() past the end of the newly allocated table.

Read disksize after acquiring dev_lock and checking that the device is

initialized. The read lock then keeps the table and its bound stable for

the duration of the scan. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-89719
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-89719