Improper locking in Linux kernel - CVE-2026-90043
Published: September 16, 2026
Vulnerability details
The vulnerability allows a local user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to improper locking in the zram slot-locking mechanism when access-time values are stored for zram slots. A local user can trigger concurrent access to the same zram slot to compromise confidentiality, integrity, and availability.
The issue affects 64-bit big-endian systems when zram access-time tracking is enabled.