Description
In the Linux kernel, the following vulnerability has been resolved:

ubifs: fix out-of-bounds read in signature length check

ubifs_sb_verify_signature() bounds the on-disk ubifs_sig_node->len field
before handing the signature payload to verify_pkcs7_signature(), but the
check has the wrong sign:

if (le32_to_cpu(signode->len) > snod->len + sizeof(struct ubifs_sig_node))

The signature bytes start sizeof(struct ubifs_sig_node) (UBIFS_SIG_NODE_SZ,
64 bytes) into the node, so the payload is at most

snod->len - sizeof(struct ubifs_sig_node)

bytes long. Adding the header size instead of subtracting it accepts a
declared length up to 2 * UBIFS_SIG_NODE_SZ larger than the node actually
holds -- past the end of c->sbuf, which is vmalloc(c->leb_size).
verify_pkcs7_signature() -> pkcs7_parse_message() -> asn1_ber_decoder()
is then handed that inflated length and reads beyond the allocation while
walking the DER headers. The node length comes straight from the mounted
image, so a crafted signed UBIFS image reaches this via
ubifs_read_superblock() before the signature is cryptographically checked.

snod->len is guaranteed to be >= UBIFS_SIG_NODE_SZ by the node scanner
(c->ranges[UBIFS_SIG_NODE].min_len == UBIFS_SIG_NODE_SZ), so the corrected
subtraction cannot underflow. Legitimately signed images are unaffected: a
correct superblock never declares a signature longer than the node it is
embedded in.
Published: 2026-09-11
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure or crash
Action: Patch kernel
AI Analysis

Impact

An improper bounds check in the UBIFS superblock signature verification logic allows a crafted signed UBIFS image to cause the kernel to read beyond the allocated buffer when parsing the signature length. The flaw does not provide remote code execution; instead it can leak kernel memory contents or trigger a kernel panic due to an out‑of‑bounds read. It exists before the fix that corrects the bounds calculation, and it affects any UBIFS‑enabled Linux kernel where the signature field is present and verified.

Affected Systems

Linux kernels that employ the UBIFS file system and run a kernel version prior to the included commit are vulnerable. The flaw is present in all Linux kernel releases that expose the ubifs_sb_verify_signature routine without the subsequent patch, regardless of distribution or vendor. The affected products, as identified by the CNA, are the Linux kernel as a whole.

Risk and Exploitability

The CVSS score of 7.7 indicates serious impact, while the EPSS score of < 1% suggests very low probability of exploitation. It is not currently listed in the CISA KEV catalog. Exploitation requires the ability to supply a malicious UBIFS image to the or via remote control of a storage medium. No direct remote code execution path exists; the attacker could achieve information disclosure or denial of service if the malformed image is mounted.

Generated by OpenCVE AI on September 15, 2026 at 19:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install a kernel package that includes the fix commit 83e1aa9f5f906c9b1f4949d0521f0f950a159d96 or newer.
  • Reboot the system to activate the updated kernel.
  • If you build your own kernel, apply the patch directly to the source tree, rebuild, and install.

Generated by OpenCVE AI on September 15, 2026 at 19:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H'}

cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ubifs: fix out-of-bounds read in signature length check ubifs_sb_verify_signature() bounds the on-disk ubifs_sig_node->len field before handing the signature payload to verify_pkcs7_signature(), but the check has the wrong sign: if (le32_to_cpu(signode->len) > snod->len + sizeof(struct ubifs_sig_node)) The signature bytes start sizeof(struct ubifs_sig_node) (UBIFS_SIG_NODE_SZ, 64 bytes) into the node, so the payload is at most snod->len - sizeof(struct ubifs_sig_node) bytes long. Adding the header size instead of subtracting it accepts a declared length up to 2 * UBIFS_SIG_NODE_SZ larger than the node actually holds -- past the end of c->sbuf, which is vmalloc(c->leb_size). verify_pkcs7_signature() -> pkcs7_parse_message() -> asn1_ber_decoder() is then handed that inflated length and reads beyond the allocation while walking the DER headers. The node length comes straight from the mounted image, so a crafted signed UBIFS image reaches this via ubifs_read_superblock() before the signature is cryptographically checked. snod->len is guaranteed to be >= UBIFS_SIG_NODE_SZ by the node scanner (c->ranges[UBIFS_SIG_NODE].min_len == UBIFS_SIG_NODE_SZ), so the corrected subtraction cannot underflow. Legitimately signed images are unaffected: a correct superblock never declares a signature longer than the node it is embedded in.
Title ubifs: fix out-of-bounds read in signature length check
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:02:12.826Z

Reserved: 2026-09-11T19:38:34.752Z

Link: CVE-2026-89720

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:20:00.943

Modified: 2026-09-14T13:19:21.230

Link: CVE-2026-89720

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:32Z

Links: CVE-2026-89720 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:30:12Z

Weaknesses