Out-of-bounds read in Linux kernel - CVE-2026-89720
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to read beyond allocated memory.
The vulnerability exists due to an out-of-bounds read in ubifs_sb_verify_signature() when mounting a crafted signed UBIFS image. A local user can provide an image with an inflated signature length to read beyond allocated memory.
The signature is processed before it is cryptographically checked.