Executive brief
eCryptfs is a cryptographic filesystem layer in the Linux kernel used to encrypt files and filenames. A flaw in how the kernel parses tag 70 encryption packets can cause an integer underflow when processing malformed packets, potentially allowing a local attacker to trigger a denial of service or cause memory corruption.
Technical details
The vulnerability is an integer underflow in ecryptfs_parse_tag_70_packet() in fs/ecryptfs/keystore.c. The function subtracts fixed metadata field sizes (signature and cipher code) from a user-supplied packet body size to calculate the encrypted filename size. If a malformed packet has a body smaller than these fixed fields, the subtraction causes an underflow, resulting in a large positive value that is then used for memory operations. This can lead to out-of-bounds reads or writes. The fix adds a validation check to reject packets smaller than ECRYPTFS_SIG_SIZE (16 bytes) plus 2 bytes (for cipher code and at least one byte of encrypted data) before performing the subtraction. A local attacker can exploit this by providing a specially crafted ecryptfs mount or packet, but does not require special privileges or user interaction beyond filesystem operations.
Affected products
- Linux Linux kernel 2.6.11 through 7.2 (eCryptfs subsystem affected since introduction)
Timeline
- 2026-09-11: disclosed: CVE-2026-89606 published
- 2026-09-14: patched: Fix committed to stable kernel branches
- 2026-07-15: other: Patch authored by Yichong Chen