CVE-2026-89717: Linux

EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: zram: set default primary compressor in zram_destroy_comps() Patch series "zram: fix zram issues reported by sashiko". Sashiko drove by and reported [1] a couple of zram issues: a possible BUG_ON() in zlib code due to missing winbits range validation and one possible NULL-ptr dereference in zcomp. Both are low risk yet still worth fixing. This patch (of 2): zram_destroy_comps() resets all compressors and leaves them set to NULL, including the primary one, which is invalid device state, as now comp_algorithm_show()->strcmp() can be called on a NULL compressor. Set default primary compressor in zram_destroy_comps().

Affected products

  • Linux Linux: from 6.6.57, before 6.7 (fixed in 6.7); from 6.11.4, before 6.12 (fixed in 6.12); from 6.12, before 6.12.111 (fixed in 6.12.111); from 6.13, before 6.18.51 (fixed in 6.18.51); from 6.19, before 7.2.4 (fixed in 7.2.4)

Published 2026-09-11. Last modified 2026-09-21.