Description
In the Linux kernel, the following vulnerability has been resolved:

ecryptfs: reject oversized encrypted_key_size in parse_tag_3_packet

parse_tag_3_packet() set encrypted_key_size from the Tag 3 packet body
without bounding it against ECRYPTFS_MAX_KEY_BYTES (64). When
encrypted_key_size > 64, decrypt_passphrase_encrypted_session_key()
sets decrypted_key_size = encrypted_key_size and performs two
out-of-bounds writes:

1. crypto_skcipher_decrypt() writes encrypted_key_size bytes into
decrypted_key[64] via scatterlist, overflowing into the parent
ecryptfs_auth_tok struct.
2. memcpy(crypt_stat->key, decrypted_key, decrypted_key_size) writes
into crypt_stat->key[64], corrupting root_iv, keysig_list, and
mutexes in ecryptfs_crypt_stat.

Only AES-192 (cipher code 0x08) enables this because it sets
crypt_stat->key_size = 24 independently of encrypted_key_size,
allowing crypto_skcipher_setkey() to succeed while encrypted_key_size
exceeds ECRYPTFS_MAX_KEY_BYTES.

The PKI decryption path (parse_tag_65_packet) already validates
decrypted_key_size <= ECRYPTFS_MAX_KEY_BYTES; the passphrase path
omits this check.

Bound encrypted_key_size against ECRYPTFS_MAX_KEY_BYTES (64) rather
than ECRYPTFS_MAX_ENCRYPTED_KEY_BYTES (512). The 64-byte limit also
protects the 512-byte encrypted_key[] buffer, so the former 512-byte
check is removed as redundant.

[tyhicks: Adjust the code comment to refer to macros representing the
buffer sizes rather than mentioning the buffer size values since they
may change in the future]
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel out‑of‑bounds write allowing arbitrary code execution
Action: Immediate Patch
AI Analysis

Impact

The flaw originates in the ecryptfs parse_tag_3_packet function, which assigns an encrypted key size to the buffer without bounding it against ECRYPTFS_MAX_KEY_BYTES (64). During decryption, crypto_skcipher_decrypt writes‑byte array and memcpy copies the oversized payload into another 64‑byte array, corrupting critical kernel structures such as root_iv, keysig_list, and mutexes. This double out‑of‑bounds write can corrupt kernel heap memory, potentially enabling an attacker to execute arbitrary code or crash the system. Only the AES‑192 cipher path is vulnerable because it sets a fixed key size of 24 bytes while allowing an oversized encrypted_key_size, giving the attacker the necessary conditions to trigger the overflow. The vulnerability essentially permits kernel memory corruption through the ecryptfs encryption layer, exposing the system to code execution or denial of service. No abuse of the flaw is formally documented in external advisories beyond the bug fix, but the description demonstrates that the conditions for exploitation exist.

Affected Systems

All Linux kernel releases that contain the ecryptfs implementation and have not incorporated the commit that bounds encrypted_key_size in specific to kernel configurations that enable AES‑192 for ecryptfs; any kernel using that cipher in ecryptfs is susceptible so any kernel prior to the patch that contains the vulnerable function should be assumed at risk.

Risk and Exploitability

The CVSS score of 7.8 denotes high severity, while the EPSS score of less than 1 % indicates a low current exploitation probability. Because it is not listed in the CISA KEV catalog, the vulnerability has not been observed in widespread targeted attacks. The likely attack vector involves creating or manipulating an ecryptfs encrypted file with a crafted Tag 3 packet, which, when decrypted, triggers the out‑of‑bounds writes. An attacker with write access to an ecryptfs mount can exploit the flaw to corrupt kernel memory, potentially achieving code execution or causing a system crash. No public exploit is reported in the CVE data, but the existence of an exploitable kernel OOB write is well documented.

Generated by OpenCVE AI on September 15, 2026 at 21:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the patch which bounds encrypted_key_size in parse_tag_3_packet.
  • After upgrading, remount all ecryptfs filesystems to ensure the new kernel code is in use.
  • If a kernel upgrade is not immediately possible, reconfigure ecryptfs to use a cipher other than AES‑192 (e.g., AES‑256) to avoid exercising the vulnerable code path.

Generated by OpenCVE AI on September 15, 2026 at 21:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H'}

threat_severity

Moderate


Sat, 12 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ecryptfs: reject oversized encrypted_key_size in parse_tag_3_packet parse_tag_3_packet() set encrypted_key_size from the Tag 3 packet body without bounding it against ECRYPTFS_MAX_KEY_BYTES (64). When encrypted_key_size > 64, decrypt_passphrase_encrypted_session_key() sets decrypted_key_size = encrypted_key_size and performs two out-of-bounds writes: 1. crypto_skcipher_decrypt() writes encrypted_key_size bytes into decrypted_key[64] via scatterlist, overflowing into the parent ecryptfs_auth_tok struct. 2. memcpy(crypt_stat->key, decrypted_key, decrypted_key_size) writes into crypt_stat->key[64], corrupting root_iv, keysig_list, and mutexes in ecryptfs_crypt_stat. Only AES-192 (cipher code 0x08) enables this because it sets crypt_stat->key_size = 24 independently of encrypted_key_size, allowing crypto_skcipher_setkey() to succeed while encrypted_key_size exceeds ECRYPTFS_MAX_KEY_BYTES. The PKI decryption path (parse_tag_65_packet) already validates decrypted_key_size <= ECRYPTFS_MAX_KEY_BYTES; the passphrase path omits this check. Bound encrypted_key_size against ECRYPTFS_MAX_KEY_BYTES (64) rather than ECRYPTFS_MAX_ENCRYPTED_KEY_BYTES (512). The 64-byte limit also protects the 512-byte encrypted_key[] buffer, so the former 512-byte check is removed as redundant. [tyhicks: Adjust the code comment to refer to macros representing the buffer sizes rather than mentioning the buffer size values since they may change in the future]
Title ecryptfs: reject oversized encrypted_key_size in parse_tag_3_packet
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:01:27.820Z

Reserved: 2026-09-11T19:38:34.733Z

Link: CVE-2026-89607

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:45.723

Modified: 2026-09-14T13:19:14.910

Link: CVE-2026-89607

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:45:09Z

Links: CVE-2026-89607 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:30:16Z

Weaknesses