---
id: CVE-2026-89169
title: >-
  live-boot ff8867c allows attackers to bypass the
  dm-verity-enforce-roothash-signature protection mechanism when the .verity
  file is missing.
summary: >-
  live-boot ff8867c allows attackers to bypass the
  dm-verity-enforce-roothash-signature protection mechanism when the .verity
  file is missing.
severity: medium
cvss: 4.1
cvssVector: 'CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-347
vendor: Debian
product: live-boot
affected:
  - live-boot ff8867c4e2d62e497cb895b15b7d6d518d5adff1
published: '2026-09-11'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T20:00:03.713'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89169'
references:
  - url: 'https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1146422'
    label: cve@mitre.org
  - url: >-
      https://salsa.debian.org/live-team/live-boot/-/blob/ff8867c4e2d62e497cb895b15b7d6d518d5adff1/components/9990-overlay.sh#L112-114
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
epss: 0.00148
epssPercentile: 0.0335
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-11T15:56:11.142588Z'
cvssSource: cna
ingestedAt: '2026-09-12T05:46:19.335Z'
---

## Overview

live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
