CVE-2026-89169 PUBLISHED

Assigner: mitre
Reserved: 11.09.2026 Published: 11.09.2026 Updated: 11.09.2026

live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.

Metrics

CVSS Vector: CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 4.1

Product Status

Vendor Debian
Product live-boot
Versions Default: unknown
  • Version ff8867c4e2d62e497cb895b15b7d6d518d5adff1 is affected

References

Problem Types

  • CWE-347 Improper Verification of Cryptographic Signature CWE