CyberRota
← Ana sayfaya dön

CVE-2026-53185

HIGH · CVSS 7.8 EPSS %0.10

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-06-25T09:16:35.920 · Çekilme zamanı: 2026-06-30T18:33:25.327376+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-53185
Severity
HIGH
CVSS
7.8
EPSS
%0.10
Linux

Orijinal NVD Açıklaması

In the Linux kernel, the following vulnerability has been resolved: zram: fix use-after-free in zram_bvec_write_partial() zram_read_page() picks the sync or async backing device read path based on whether the parent bio is NULL. zram_bvec_write_partial() passes its parent bio down, so for ZRAM_WB slots the read is dispatched asynchronously and zram_read_page() returns 0 while the bio is still in flight. The caller then runs memcpy_from_bvec(), zram_write_page() and __free_page() on the buffer, leaving the async read to write into a freed page. zram_bvec_read_partial() was switched to NULL in commit 4e3c87b9421d ("zram: fix synchronous reads") for the same reason; the write_partial counterpart was missed.