CVE-2026-89606

high

Description

In the Linux kernel, the following vulnerability has been resolved: ecryptfs: reject too-small tag 70 packets ecryptfs_parse_tag_70_packet() subtracts fixed metadata fields from the parsed packet body size to derive the encrypted filename size. A malformed packet with a body smaller than those fixed fields can underflow that size calculation. Reject tag 70 packets before the subtraction unless the body contains the signature, cipher code, and at least one byte of encrypted filename data.

References

https://git.kernel.org/stable/c/e97bbe1b2bd82ec2ae37ad2e4965b4d3e78bbf7f

https://git.kernel.org/stable/c/df5f375a6151ef71f636da044bcef90c26697255

https://git.kernel.org/stable/c/d2869768eab5648e6edc05f47e0716e5328e6681

https://git.kernel.org/stable/c/b31da1ecf13929a8d7f8d2727843d2fe35396b75

https://git.kernel.org/stable/c/9d88391bbed76eb091cddd50b0af87b1c6f22589

https://git.kernel.org/stable/c/5668121974eb7f7aa82793a9d0d13abadb8904dc

https://git.kernel.org/stable/c/414a0f04feb06f03523edf7e2a8be1d7f1a9b160

https://git.kernel.org/stable/c/2e5afed9503dd1d85004c09503adc2cb584c0188

Details

Source: Mitre, NVD

Published: 2026-09-11

Updated: 2026-09-14

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00175