* CVE-2026-89720: ubifs: fix out-of-bounds read in signature length check
@ 2026-09-11 19:46 Greg Kroah-Hartman
0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-11 19:46 UTC (permalink / raw)
To: linux-cve-announce; +Cc: Greg Kroah-Hartman
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
ubifs: fix out-of-bounds read in signature length check
ubifs_sb_verify_signature() bounds the on-disk ubifs_sig_node->len field
before handing the signature payload to verify_pkcs7_signature(), but the
check has the wrong sign:
if (le32_to_cpu(signode->len) > snod->len + sizeof(struct ubifs_sig_node))
The signature bytes start sizeof(struct ubifs_sig_node) (UBIFS_SIG_NODE_SZ,
64 bytes) into the node, so the payload is at most
snod->len - sizeof(struct ubifs_sig_node)
bytes long. Adding the header size instead of subtracting it accepts a
declared length up to 2 * UBIFS_SIG_NODE_SZ larger than the node actually
holds -- past the end of c->sbuf, which is vmalloc(c->leb_size).
verify_pkcs7_signature() -> pkcs7_parse_message() -> asn1_ber_decoder()
is then handed that inflated length and reads beyond the allocation while
walking the DER headers. The node length comes straight from the mounted
image, so a crafted signed UBIFS image reaches this via
ubifs_read_superblock() before the signature is cryptographically checked.
snod->len is guaranteed to be >= UBIFS_SIG_NODE_SZ by the node scanner
(c->ranges[UBIFS_SIG_NODE].min_len == UBIFS_SIG_NODE_SZ), so the corrected
subtraction cannot underflow. Legitimately signed images are unaffected: a
correct superblock never declares a signature longer than the node it is
embedded in.
The Linux kernel CVE team has assigned CVE-2026-89720 to this issue.
Affected and fixed versions
===========================
Issue introduced in 5.3 with commit 817aa094842dfc3a6b98c9582d4a647827f66201 and fixed in 6.12.109 with commit f76b79d6e42af20682495bccd22f72c7164b0018
Issue introduced in 5.3 with commit 817aa094842dfc3a6b98c9582d4a647827f66201 and fixed in 6.18.50 with commit a1dc246f98bb94233effa4fa3ec7bf84700bb7d1
Issue introduced in 5.3 with commit 817aa094842dfc3a6b98c9582d4a647827f66201 and fixed in 7.2.4 with commit 83e1aa9f5f906c9b1f4949d0521f0f950a159d96
Issue introduced in 5.3 with commit 817aa094842dfc3a6b98c9582d4a647827f66201 and fixed in 7.3-rc1 with commit 95d27c1708bb6e8823c8e7c623f9abc2a91bf4bf
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-89720
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
fs/ubifs/auth.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/f76b79d6e42af20682495bccd22f72c7164b0018
https://git.kernel.org/stable/c/a1dc246f98bb94233effa4fa3ec7bf84700bb7d1
https://git.kernel.org/stable/c/83e1aa9f5f906c9b1f4949d0521f0f950a159d96
https://git.kernel.org/stable/c/95d27c1708bb6e8823c8e7c623f9abc2a91bf4bf
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-09-11 20:04 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-11 19:46 CVE-2026-89720: ubifs: fix out-of-bounds read in signature length check Greg Kroah-Hartman
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.