# CVE-2026-89720

## Summary

- **CVE ID:** CVE-2026-89720
- **Severity:** HIGH
- **CVSS Score:** 7.7 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 14, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

ubifs: fix out-of-bounds read in signature length check

ubifs_sb_verify_signature() bounds the on-disk ubifs_sig_node->len field
before handing the signature payload to verify_pkcs7_signature(), but the
check has the wrong sign:

	if (le32_to_cpu(signode->len) > snod->len + sizeof(struct ubifs_sig_node))

The signature bytes start sizeof(struct ubifs_sig_node) (UBIFS_SIG_NODE_SZ,
64 bytes) into the node, so the payload is at most

	snod->len - sizeof(struct ubifs_sig_node)

bytes long. Adding the header size instead of subtracting it accepts a
declared length up to 2 * UBIFS_SIG_NODE_SZ larger than the node actually
holds -- past the end of c->sbuf, which is vmalloc(c->leb_size).
verify_pkcs7_signature() -> pkcs7_parse_message() -> asn1_ber_decoder()
is then handed that inflated length and reads beyond the allocation while
walking the DER headers. The node length comes straight from the mounted
image, so a crafted signed UBIFS image reaches this via
ubifs_read_superblock() before the signature is cryptographically checked.

snod->len is guaranteed to be >= UBIFS_SIG_NODE_SZ by the node scanner
(c->ranges[UBIFS_SIG_NODE].min_len == UBIFS_SIG_NODE_SZ), so the corrected
subtraction cannot underflow. Legitimately signed images are unaffected: a
correct superblock never declares a signature longer than the node it is
embedded in.

## Affected Products

- Linux — Linux (817aa094842dfc3a6b98c9582d4a647827f66201)
- Linux — Linux (5.3)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)
- Linux — Linux (5.10.270)
- Linux — Linux (5.15.221)
- Linux — Linux (6.1.188)
- Linux — Linux (6.6.157)

## References

- [CNA](https://git.kernel.org/stable/c/f76b79d6e42af20682495bccd22f72c7164b0018)
- [CNA](https://git.kernel.org/stable/c/a1dc246f98bb94233effa4fa3ec7bf84700bb7d1)
- [CNA](https://git.kernel.org/stable/c/83e1aa9f5f906c9b1f4949d0521f0f950a159d96)
- [CNA](https://git.kernel.org/stable/c/95d27c1708bb6e8823c8e7c623f9abc2a91bf4bf)
- [CNA](https://git.kernel.org/stable/c/ab7405bd86331cc2dbc8201699d4adc33bea75e7)
- [CNA](https://git.kernel.org/stable/c/11abc34698cb3172badf8aa12e623f1bac98bbd8)
- [CNA](https://git.kernel.org/stable/c/8cc3da72cf57acb4b77442ea8cec48425dff7c06)
- [CNA](https://git.kernel.org/stable/c/37a9d25a563f5f9103282954ce573c4a61321e7c)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.18%
- **EPSS Percentile:** 8.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._