CVE-2026-53185CWE-364CWE-416

CVE-2026-53185

High · published June 25, 2026

CVSS v3.1
7.8
EPSS
0%
Percentile
1.0
In the wild
Unconfirmed
What it is

In the Linux kernel, the following vulnerability has been resolved:

zram: fix use-after-free in zram_bvec_write_partial()

zram_read_page() picks the sync or async backing device read path based on

whether the parent bio is NULL. zram_bvec_write_partial() passes its

parent bio down, so for ZRAM_WB slots the read is dispatched

asynchronously and zram_read_page() returns 0 while the bio is still in

flight. The caller then runs memcpy_from_bvec(), zram_write_page() and

__free_page() on the buffer, leaving the async read to write into a freed

page.

zram_bvec_read_partial() was switched to NULL in commit 4e3c87b9421d

("zram: fix synchronous reads") for the same reason; the write_partial

counterpart was missed.

The record
Technical detail
CVSS v3.1
7.8 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00102 · 1.0th percentile
Weaknesses
CWE-364 · Signal Handler Race Condition; CWE-416 · Use After Free
Published
2026-06-25T13:16Z
Affected products (11)
ProductVersionsFixed in
linux/linux_kernel≥ 4.14, < 6.6.1436.6.143
linux/linux_kernel≥ 6.7, < 6.12.946.12.94
linux/linux_kernel≥ 6.13, < 6.18.366.18.36
linux/linux_kernel≥ 6.19, < 7.0.137.0.13
linux/linux_kernelall versions
linux/linux_kernelall versions
linux/linux_kernelall versions
linux/linux_kernelall versions
linux/linux_kernelall versions
linux/linux_kernelall versions
linux/linux_kernelall versions
References (12)
EPSS history
Timeline
  • 25 JUN 08:38Z
    zram: fix use-after-free in zram_bvec_write_partial()
    cvelistv5