In the Linux kernel, the following vulnerability has been resolved: ubifs: fix out-of-bounds read in signature length check… (CVE-2026-89720)
A vulnerability in the Linux kernel's UBIFS filesystem code allowed an out-of-bounds read due to an incorrect bounds check on the signature length. This flaw could be triggered by a crafted signed UBIFS image, causing the kernel to read beyond allocated memory while verifying the signature. Legitimately signed images are unaffected. The issue has been resolved in the Linux kernel.
AI Analysis
Technical Summary
The vulnerability in the Linux kernel's UBIFS subsystem involved an incorrect sign in the bounds check of the on-disk ubifs_sig_node->len field before passing the signature payload to verify_pkcs7_signature(). The check erroneously added the header size instead of subtracting it, allowing a declared signature length up to twice the header size larger than the actual node size. This caused verify_pkcs7_signature() and subsequent ASN.1 parsing functions to read beyond the allocated buffer, leading to an out-of-bounds read. The flaw could be triggered by a crafted signed UBIFS image during superblock reading before cryptographic signature verification. The node length is guaranteed to be at least the header size, so the corrected subtraction does not underflow. Legitimate images are unaffected as they never declare an oversized signature.
Potential Impact
An attacker able to supply a crafted signed UBIFS image could cause the kernel to perform an out-of-bounds read during signature verification. This could potentially lead to information disclosure or kernel memory corruption depending on the context of the read. However, legitimate signed images are not affected, and no known exploits are reported in the wild.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to correct the bounds check by subtracting the header size instead of adding it. Users should update to the patched Linux kernel version containing this fix. No additional mitigation is required for legitimately signed images.
In the Linux kernel, the following vulnerability has been resolved: ubifs: fix out-of-bounds read in signature length check… (CVE-2026-89720)
Description
A vulnerability in the Linux kernel's UBIFS filesystem code allowed an out-of-bounds read due to an incorrect bounds check on the signature length. This flaw could be triggered by a crafted signed UBIFS image, causing the kernel to read beyond allocated memory while verifying the signature. Legitimately signed images are unaffected. The issue has been resolved in the Linux kernel.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in the Linux kernel's UBIFS subsystem involved an incorrect sign in the bounds check of the on-disk ubifs_sig_node->len field before passing the signature payload to verify_pkcs7_signature(). The check erroneously added the header size instead of subtracting it, allowing a declared signature length up to twice the header size larger than the actual node size. This caused verify_pkcs7_signature() and subsequent ASN.1 parsing functions to read beyond the allocated buffer, leading to an out-of-bounds read. The flaw could be triggered by a crafted signed UBIFS image during superblock reading before cryptographic signature verification. The node length is guaranteed to be at least the header size, so the corrected subtraction does not underflow. Legitimate images are unaffected as they never declare an oversized signature.
Potential Impact
An attacker able to supply a crafted signed UBIFS image could cause the kernel to perform an out-of-bounds read during signature verification. This could potentially lead to information disclosure or kernel memory corruption depending on the context of the read. However, legitimate signed images are not affected, and no known exploits are reported in the wild.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to correct the bounds check by subtracting the header size instead of adding it. Users should update to the patched Linux kernel version containing this fix. No additional mitigation is required for legitimately signed images.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-8388-259p-82vg
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-89720"]
Threat ID: 6aa49fff55bf5e2cf5a865fb
Added to database: 09/12/2026, 00:42:39 UTC
Last enriched: 09/12/2026, 00:53:46 UTC
Last updated: 09/12/2026, 00:53:46 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.