---
id: CVE-2026-89720
title: >-
  kernel: ubifs: fix out-of-bounds read in signature length check
  (CVE-2026-89720)
summary: >-
  A flaw was found in the Linux kernel's Unsorted Block Image File System
  (UBIFS). An incorrect bounds check in the ubifs_sb_verify_signature() function
  allows a crafted signed UBIFS image to declare a signature length larger than
  its actual…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-125
vendor: Red Hat
product: Linux
affected:
  - >-
    Linux >= 817aa094842dfc3a6b98c9582d4a647827f66201 <
    ab7405bd86331cc2dbc8201699d4adc33bea75e7
  - >-
    Linux >= 817aa094842dfc3a6b98c9582d4a647827f66201 <
    11abc34698cb3172badf8aa12e623f1bac98bbd8
  - >-
    Linux >= 817aa094842dfc3a6b98c9582d4a647827f66201 <
    8cc3da72cf57acb4b77442ea8cec48425dff7c06
  - >-
    Linux >= 817aa094842dfc3a6b98c9582d4a647827f66201 <
    37a9d25a563f5f9103282954ce573c4a61321e7c
  - >-
    Linux >= 817aa094842dfc3a6b98c9582d4a647827f66201 <
    f76b79d6e42af20682495bccd22f72c7164b0018
  - >-
    Linux >= 817aa094842dfc3a6b98c9582d4a647827f66201 <
    a1dc246f98bb94233effa4fa3ec7bf84700bb7d1
  - >-
    Linux >= 817aa094842dfc3a6b98c9582d4a647827f66201 <
    83e1aa9f5f906c9b1f4949d0521f0f950a159d96
  - >-
    Linux >= 817aa094842dfc3a6b98c9582d4a647827f66201 <
    95d27c1708bb6e8823c8e7c623f9abc2a91bf4bf
  - Linux 5.3
published: '2026-09-11'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T20:24:19+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89720.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89720.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-89720'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2532147'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-89720'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89720'
  - url: >-
      https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89720.mbox
  - url: 'https://git.kernel.org/stable/c/ab7405bd86331cc2dbc8201699d4adc33bea75e7'
  - url: 'https://git.kernel.org/stable/c/11abc34698cb3172badf8aa12e623f1bac98bbd8'
  - url: 'https://git.kernel.org/stable/c/8cc3da72cf57acb4b77442ea8cec48425dff7c06'
  - url: 'https://git.kernel.org/stable/c/37a9d25a563f5f9103282954ce573c4a61321e7c'
  - url: 'https://git.kernel.org/stable/c/f76b79d6e42af20682495bccd22f72c7164b0018'
  - url: 'https://git.kernel.org/stable/c/a1dc246f98bb94233effa4fa3ec7bf84700bb7d1'
  - url: 'https://git.kernel.org/stable/c/83e1aa9f5f906c9b1f4949d0521f0f950a159d96'
  - url: 'https://git.kernel.org/stable/c/95d27c1708bb6e8823c8e7c623f9abc2a91bf4bf'
tags:
  - csaf
  - vex
  - red-hat
  - cve.org
  - score-dispute
epss: 0.00182
epssPercentile: 0.08073
scores:
  vendor: 5.5
  cna: 7.7
ingestedAt: '2026-09-14T15:23:07.449Z'
---

## Overview

A flaw was found in the Linux kernel's Unsorted Block Image File System (UBIFS). An incorrect bounds check in the ubifs_sb_verify_signature() function allows a crafted signed UBIFS image to declare a signature length larger than its actual size. This can lead to an out-of-bounds read when processing the signature, potentially causing information disclosure or a system crash (Denial of Service).

## Vendor advisories

- **Red Hat VEX** · Moderate · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89720.json)

**kernel: ubifs: fix out-of-bounds read in signature length check** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-15.

Not affected:

- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4

## Remediation

Refer to the advisory for fix availability.
