Type Confusion Vulnerability in Linux Kernel Affecting Big-Endian Systems
CVE-2026-90043

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-90043?

A vulnerability has been identified in the Linux kernel that affects how the zram module handles locking on big-endian 64-bit systems. The issue arises from improper bit manipulation regarding slot locks, where the lock bit is incorrectly positioned. This discrepancy allows for potential race conditions where another CPU could mistakenly access a locked slot, leading to erroneous behaviors in memory handling. The vulnerability has been addressed by shifting the lock bit into the correct position within the flags field, ensuring proper synchronization and operation across CPUs.

Affected Version(s)

Linux 2e8ff2f51dde73a26b94aed2df4827177bd25e6e < 052b6b2d5fe97547bd2cdb73fa894f6cfea68b11

Linux 2e8ff2f51dde73a26b94aed2df4827177bd25e6e

Linux 7.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.