---
cve: "CVE-2026-53185"
severity: "HIGH"
cvss: 7.8
epss: "10%"
vendor: "Linux"
kev: false
exploited: false
published: "2026-06-25 09:16:35"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-08T02:30:19+02:00"
---

# CVE-2026-53185

> 7.8 HIGH

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

zram: fix use-after-free in zram_bvec_write_partial()

zram_read_page() picks the sync or async backing device read path based on
whether the parent bio is NULL.  zram_bvec_write_partial() passes its
parent bio down, so for ZRAM_WB slots the read is dispatched
asynchronously and zram_read_page() returns 0 while the bio is still in
flight.  The caller then runs memcpy_from_bvec(), zram_write_page() and
__free_page() on the buffer, leaving the async read to write into a freed
page.

zram_bvec_read_partial() was switched to NULL in commit 4e3c87b9421d
("zram: fix synchronous reads") for the same reason; the write_partial
counterpart was missed.

## CVSS-Vektor

```
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- Kernel ≥ 6.6.143
- Kernel ≥ 6.12.94
- Kernel ≥ 6.18.36
- Kernel ≥ 7.0.13

## Referenzen

- <https://git.kernel.org/stable/c/0c2821665ff71be3f4b07ecece384669f2877f6a>
- <https://git.kernel.org/stable/c/77a602b505ce4802915853cfc435a4722fab3e64>
- <https://git.kernel.org/stable/c/c96786d6ff1acc1d54d9241e97767554c1dfdd5b>
- <https://git.kernel.org/stable/c/198b5a14cca27263b9c14b20114c8092de15dfcb>
- <https://git.kernel.org/stable/c/732fd9f0b9c1cdc6dfd77162ded60df005182cc0>
- <https://access.redhat.com/errata/RHSA-2026:59723>
- <https://access.redhat.com/errata/RHSA-2026:61887>
- <https://access.redhat.com/errata/RHSA-2026:63013>
- <https://access.redhat.com/errata/RHSA-2026:63014>
- <https://access.redhat.com/security/cve/CVE-2026-53185>
- <https://bugzilla.redhat.com/show_bug.cgi?id=2492735>
- <https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53185.json>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-53185) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
