{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89608","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.733Z","datePublished":"2026-09-11T19:45:10.318Z","dateUpdated":"2026-09-14T12:01:28.889Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:01:28.889Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\necryptfs: pass packet set buffer size to parser\n\necryptfs_parse_packet_set() receives a pointer into the file header, but\nit calculates the remaining packet buffer size from PAGE_SIZE - 8.  For\nversion 1 headers the packet set starts later in the header, so this can\noverstate the available buffer.\n\nPass the actual packet set buffer length from the caller and calculate\nper-packet limits from the remaining bytes in that buffer.  Recompute the\nremaining length after consuming a tag 3 packet before parsing the\nfollowing tag 11 packet."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The over-read is reached only by a local open or setattr on an eCryptfs mount (ecryptfs_open/ecryptfs_setattr → ecryptfs_read_metadata → ecryptfs_parse_packet_set) which parses the attacker-supplied lower-file header or xattr; this is not a network protocol path.\nAC:L - Opening a crafted eCryptfs file deterministically feeds attacker-controlled version-1 headers and Tag 1/3/11 lengths into parse_packet_set(), which then uses an overstated PAGE_SIZE-8 bound; no race or uninfluenced memory layout is required.\nPR:L - An unprivileged user reaches this on standard eCryptfs deployments (setuid-root mount.ecryptfs_private and per-user encrypted home/Private) by planting a crafted file in their own lower directory and opening it through the already-mounted tree; init-namespace root is not required.\nUI:N - The attacker writes the malformed header into their lower directory and opens the corresponding eCryptfs file themselves; no action by another user is required.\nS:U - The out-of-bounds header-slab read and any resulting oops stay inside the host kernel eCryptfs code; this is not a VM escape, IOMMU bypass, or other cross-authority breakout.\nC:H - parse_packet_set() treats PAGE_SIZE-8 as the packet-set limit even after the version-1 header advances the pointer, and Tag 11 is parsed with the pre-Tag-3 remainder so max_packet_size can underflow; subsequent Tag 1 copies up to 512 bytes from adjacent slab/pages, an OOB read rated High unless a few bytes.\nI:N - Packet parsers memcpy into size-checked destinations (encrypted_key[], sig_tmp_space[8]); this bug is a source over-read of the PAGE_SIZE header cache object, not an out-of-bounds write, UAF, or control-flow hijack primitive.\nA:H - After the size_t remainder underflows, src[i] and later memcpy() walk off the header cache object into adjacent or unmapped pages and can oops; the attacker can reopen the crafted file to crash the host at will."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ecryptfs/crypto.c","fs/ecryptfs/ecryptfs_kernel.h","fs/ecryptfs/keystore.c"],"versions":[{"version":"237fead619984cc48818fe12ee0ceada3f55b012","lessThan":"e7573b0e3058c6bbdfe81673f22c09900fde9e65","status":"affected","versionType":"git"},{"version":"237fead619984cc48818fe12ee0ceada3f55b012","lessThan":"66a87559ecb26afe80ad512faf728a158e2b81da","status":"affected","versionType":"git"},{"version":"237fead619984cc48818fe12ee0ceada3f55b012","lessThan":"3bd9bb3e167a7c14a50423f6ff03ee0fb007199d","status":"affected","versionType":"git"},{"version":"237fead619984cc48818fe12ee0ceada3f55b012","lessThan":"749fa08d8f1b318bd8f4669a14a8a4a8c1bbdaac","status":"affected","versionType":"git"},{"version":"237fead619984cc48818fe12ee0ceada3f55b012","lessThan":"329de8b9e988b152b938f09224670d97bada0b96","status":"affected","versionType":"git"},{"version":"237fead619984cc48818fe12ee0ceada3f55b012","lessThan":"e5d254e654f2311a3c4b9c791d7f216554bcd17a","status":"affected","versionType":"git"},{"version":"237fead619984cc48818fe12ee0ceada3f55b012","lessThan":"747fd45be396a6aea3420ab657a0ab4e60185b05","status":"affected","versionType":"git"},{"version":"237fead619984cc48818fe12ee0ceada3f55b012","lessThan":"2602b79c5b3e2f6fce12e38a670f8e3fda4e46a2","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ecryptfs/crypto.c","fs/ecryptfs/ecryptfs_kernel.h","fs/ecryptfs/keystore.c"],"versions":[{"version":"2.6.19","status":"affected"},{"version":"0","lessThan":"2.6.19","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.19","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.19","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.19","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.19","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.19","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.19","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.19","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.19","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/e7573b0e3058c6bbdfe81673f22c09900fde9e65"},{"url":"https://git.kernel.org/stable/c/66a87559ecb26afe80ad512faf728a158e2b81da"},{"url":"https://git.kernel.org/stable/c/3bd9bb3e167a7c14a50423f6ff03ee0fb007199d"},{"url":"https://git.kernel.org/stable/c/749fa08d8f1b318bd8f4669a14a8a4a8c1bbdaac"},{"url":"https://git.kernel.org/stable/c/329de8b9e988b152b938f09224670d97bada0b96"},{"url":"https://git.kernel.org/stable/c/e5d254e654f2311a3c4b9c791d7f216554bcd17a"},{"url":"https://git.kernel.org/stable/c/747fd45be396a6aea3420ab657a0ab4e60185b05"},{"url":"https://git.kernel.org/stable/c/2602b79c5b3e2f6fce12e38a670f8e3fda4e46a2"}],"title":"ecryptfs: pass packet set buffer size to parser","x_generator":{"engine":"bippy-1.2.0"}}}}