Description
In the Linux kernel, the following vulnerability has been resolved:

ecryptfs: pass packet set buffer size to parser

ecryptfs_parse_packet_set() receives a pointer into the file header, but
it calculates the remaining packet buffer size from PAGE_SIZE - 8. For
version 1 headers the packet set starts later in the header, so this can
overstate the available buffer.

Pass the actual packet set buffer length from the caller and calculate
per-packet limits from the remaining bytes in that buffer. Recompute the
remaining length after consuming a tag 3 packet before parsing the
following tag 11 packet.
Published: 2026-09-11
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Buffer overflow in eCryptfs packet parsing
Action: Patch Now
AI Analysis

Impact

eCryptfs_parse_packet_set() receives a pointer into the file header, but it calculates the remaining packet buffer size from PAGE_SIZE - 8. For version 1 headers the packet set starts later in the header, so this can overstate the available buffer. This overestimation can cause the function to read beyond the intended data boundaries, potentially leading to kernel memory corruption that may result in a crash or, if exploited further, compromise the integrity of the kernel. The flaw is a classic buffer overflow vulnerability (CWE-131).

Affected Systems

All Linux kernel builds that include the eCryptfs subsystem and lack the upstream commit that fixes ecryptfs_parse_packet_set() remain affected. Kernel versions prior to the patch that applies the corrected buffer size calculation are vulnerable release contains the commit that modifies the packet parsing logic.

Risk and Exploitability

The likely attack vector is local or requires privileged access, as the vulnerability requires the victim to process a crafted eCryptfs packet set during file parsing when an eCryptfs encrypted file is accessed or mounted. The CVSS score of 7.1 reflects a medium‑to‑high severity, while the EPSS score of less than 1% indicates a low exploitation probability at present. Because the flaw requires the victim to process a crafted encrypted file, remote exploitation would need a separate vector to supply the malformed data. The vulnerability is not currently listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 15, 2026 at 21:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that includes the eCryptfs_parse_packet_set fix.
  • If an immediate kernel update is not feasible, unload or disable the eCryptfs module (e.g., with modprobe -r ecryptfs) or avoid mounting eCryptfs volumes until a patched kernel is available.
  • Monitor kernel logs and crash dumps for eCryptfs‑related Oops or panic entries, and investigate any anomalies promptly.

Generated by OpenCVE AI on September 15, 2026 at 21:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H'}

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-131
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ecryptfs: pass packet set buffer size to parser ecryptfs_parse_packet_set() receives a pointer into the file header, but it calculates the remaining packet buffer size from PAGE_SIZE - 8. For version 1 headers the packet set starts later in the header, so this can overstate the available buffer. Pass the actual packet set buffer length from the caller and calculate per-packet limits from the remaining bytes in that buffer. Recompute the remaining length after consuming a tag 3 packet before parsing the following tag 11 packet.
Title ecryptfs: pass packet set buffer size to parser
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:01:28.889Z

Reserved: 2026-09-11T19:38:34.733Z

Link: CVE-2026-89608

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:45.860

Modified: 2026-09-14T13:19:15.080

Link: CVE-2026-89608

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:45:10Z

Links: CVE-2026-89608 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:30:16Z

Weaknesses
  • CWE-131

    Incorrect Calculation of Buffer Size