SB2026091263 - Out-of-bounds read in Linux kernel ubifs
Published: September 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-89720)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to read beyond allocated memory.
The vulnerability exists due to an out-of-bounds read in ubifs_sb_verify_signature() when mounting a crafted signed UBIFS image. A local user can provide an image with an inflated signature length to read beyond allocated memory.
The signature is processed before it is cryptographically checked.
Remediation
Install update from vendor's website.