A vulnerability in the Linux kernel's zram module causes the blkdiscard command to hang indefinitely when issuing partial discard requests. (CVE-2026-46089)
A vulnerability in the Linux kernel's zram module causes the blkdiscard command to hang indefinitely when issuing partial discard requests. This occurs because zram does not support partial discards and fails to properly complete the I/O operation, leading to a hang in submit_bio_wait(). The issue has been fixed by ensuring bio_endio() is called to end the I/O operation correctly.
AI Analysis
Technical Summary
The Linux kernel zram module mishandles partial discard requests by not calling bio_endio(), causing blkdiscard to hang indefinitely in submit_bio_wait(). This bug was reported by Qu Wenruo and Avinesh Kumar and affects version 3.0 of the kernel. The fix involves jumping to the end_bio label to properly complete the I/O operation, preventing the indefinite sleep.
Potential Impact
The vulnerability results in a denial of service condition where blkdiscard commands with partial discard requests hang indefinitely, potentially impacting system operations that rely on zram discard functionality. There is no confidentiality or integrity impact reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no patch links or official fix information is provided, users should monitor vendor advisories for updates. Avoid issuing partial discard requests on affected versions until a fix is confirmed.
A vulnerability in the Linux kernel's zram module causes the blkdiscard command to hang indefinitely when issuing partial discard requests. (CVE-2026-46089)
Description
A vulnerability in the Linux kernel's zram module causes the blkdiscard command to hang indefinitely when issuing partial discard requests. This occurs because zram does not support partial discards and fails to properly complete the I/O operation, leading to a hang in submit_bio_wait(). The issue has been fixed by ensuring bio_endio() is called to end the I/O operation correctly.
CVSS v3.1
Score 5.5medium
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel zram module mishandles partial discard requests by not calling bio_endio(), causing blkdiscard to hang indefinitely in submit_bio_wait(). This bug was reported by Qu Wenruo and Avinesh Kumar and affects version 3.0 of the kernel. The fix involves jumping to the end_bio label to properly complete the I/O operation, preventing the indefinite sleep.
Potential Impact
The vulnerability results in a denial of service condition where blkdiscard commands with partial discard requests hang indefinitely, potentially impacting system operations that rely on zram discard functionality. There is no confidentiality or integrity impact reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no patch links or official fix information is provided, users should monitor vendor advisories for updates. Avoid issuing partial discard requests on affected versions until a fix is confirmed.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_vex
- Csaf Version
- 2.0
- Publisher
- Microsoft Security Response Center
- Advisory Id
- msrc_CVE-2026-46089
- Cve Count
- 1
- Additional Cves
- []
- Cvss Version
- 3.1
Threat ID: 6a18ab86e29bf47b50288fb9
Added to database: 05/28/2026, 20:54:30 UTC
Last enriched: 06/26/2026, 23:38:49 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 44
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.