High · published June 25, 2026
In the Linux kernel, the following vulnerability has been resolved:
zram: fix use-after-free in zram_bvec_write_partial()
zram_read_page() picks the sync or async backing device read path based on
whether the parent bio is NULL. zram_bvec_write_partial() passes its
parent bio down, so for ZRAM_WB slots the read is dispatched
asynchronously and zram_read_page() returns 0 while the bio is still in
flight. The caller then runs memcpy_from_bvec(), zram_write_page() and
__free_page() on the buffer, leaving the async read to write into a freed
page.
zram_bvec_read_partial() was switched to NULL in commit 4e3c87b9421d
("zram: fix synchronous reads") for the same reason; the write_partial
counterpart was missed.
| Product | Versions | Fixed in |
|---|---|---|
| linux/linux_kernel | ≥ 4.14, < 6.6.143 | 6.6.143 |
| linux/linux_kernel | ≥ 6.7, < 6.12.94 | 6.12.94 |
| linux/linux_kernel | ≥ 6.13, < 6.18.36 | 6.18.36 |
| linux/linux_kernel | ≥ 6.19, < 7.0.13 | 7.0.13 |
| linux/linux_kernel | all versions | — |
| linux/linux_kernel | all versions | — |
| linux/linux_kernel | all versions | — |
| linux/linux_kernel | all versions | — |
| linux/linux_kernel | all versions | — |
| linux/linux_kernel | all versions | — |
| linux/linux_kernel | all versions | — |