Always-Incorrect Control Flow Implementation in Linux kernel - CVE-2026-46089
Published: May 27, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of partial discard requests in zram when processing discard operations. A local user can issue a partial discard request to cause a denial of service.
The issue can cause the calling process to sleep indefinitely in submit_bio_wait().
How to mitigate CVE-2026-46089
Sources
- https://git.kernel.org/stable/c/2d1f18efccdb8b29552399d024c36b705447e975
- https://git.kernel.org/stable/c/35d3300f6357cfaa72db2721dc2b345b19bac5df
- https://git.kernel.org/stable/c/68ce397e8236088fc53b9532d383a722288c8194
- https://git.kernel.org/stable/c/a02363f71a79b755daa78a70d6b217f9c13c8c85
- https://git.kernel.org/stable/c/e3668b371329ea036ff022ce8ecc82f8befcf003