Description
live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.
Published: 2026-09-11
Score: 4.1 Medium
EPSS: n/a
KEV: No
Impact: Bypass of dm-verity enforcement
Action: Patch Immediately
AI Analysis

Impact

The vulnerability in Debian live-boot allows an attacker to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is absent from the system. This flaw permits the system to boot without verifying the integrity of the root filesystem, effectively removing a foundational security guard that ensures the operating system has not been tampered with. The danger is that an attacker who can manipulate the boot environment may introduce or modify system binaries before the system becomes operational, thereby compromising confidentiality, integrity, and availability of the device.

Affected Systems

Affected product: Debian live-boot, commit ff8867c. No specific version range is listed in the advisory, but the vulnerability applies to builds containing this commit until the fix is applied. All Debian systems using live-boot that include this patch are at risk until updated.

Risk and Exploitability

The CVSS score of 4.1 places the vulnerability in the moderate range, indicating that it is not trivial but still significant. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation is currently documented. The likely attack vector is local or requires the attacker to have a foothold that permits removal or disabling of the .verity file on the boot media. As such, an attacker who can alter the boot components or grid the system with malicious scripts would be able to exploit this flaw. Given the medium severity and the local nature of the threat, system owners should treat this as an actionable risk until a patch is applied.

Generated by OpenCVE AI on September 11, 2026 at 06:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Debian live-boot update that includes the dm-verity file presence check.
  • Verify that the .verity file is present on all boot media and that its signature matches the expected root hash.
  • Configure the system to prevent deletion or modification of the .verity file, for example by setting appropriate file permissions or using a read‑only filesystem for the boot partition.

Generated by OpenCVE AI on September 11, 2026 at 06:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Title Bypass of dm-verity enforcement when .verity file missing in Debian live-boot

Fri, 11 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Description live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.
Weaknesses CWE-347
References
Metrics cvssV4_0

{'score': 4.1, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-11T05:19:34.404Z

Reserved: 2026-09-11T04:44:26.012Z

Link: CVE-2026-89169

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T05:16:38.840

Modified: 2026-09-11T06:16:23.713

Link: CVE-2026-89169

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T06:30:05Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature