# CVE-2026-89169

## Summary

- **CVE ID:** CVE-2026-89169
- **Severity:** MEDIUM
- **CVSS Score:** 4.1 (CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-347
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 11, 2026

## Description

live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.

## Affected Products

- Debian — live-boot (ff8867c4e2d62e497cb895b15b7d6d518d5adff1)

## References

- [CNA](https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1146422)
- [CNA](https://salsa.debian.org/live-team/live-boot/-/blob/ff8867c4e2d62e497cb895b15b7d6d518d5adff1/components/9990-overlay.sh#L112-114)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.11%
- **EPSS Percentile:** 1.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._