Junglewise Threat Intelligence

CVE-2026-89606: Linux kernel ecryptfs integer underflow in tag 70 packet parsing

CVE-2026-89606 · Severity: high · CVSS 7.8 · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

eCryptfs is a cryptographic filesystem layer in the Linux kernel used to encrypt files and filenames. A flaw in how the kernel parses tag 70 encryption packets can cause an integer underflow when processing malformed packets, potentially allowing a local attacker to trigger a denial of service or cause memory corruption.

Technical details

The vulnerability is an integer underflow in ecryptfs_parse_tag_70_packet() in fs/ecryptfs/keystore.c. The function subtracts fixed metadata field sizes (signature and cipher code) from a user-supplied packet body size to calculate the encrypted filename size. If a malformed packet has a body smaller than these fixed fields, the subtraction causes an underflow, resulting in a large positive value that is then used for memory operations. This can lead to out-of-bounds reads or writes. The fix adds a validation check to reject packets smaller than ECRYPTFS_SIG_SIZE (16 bytes) plus 2 bytes (for cipher code and at least one byte of encrypted data) before performing the subtraction. A local attacker can exploit this by providing a specially crafted ecryptfs mount or packet, but does not require special privileges or user interaction beyond filesystem operations.

Affected products

  • Linux Linux kernel 2.6.11 through 7.2 (eCryptfs subsystem affected since introduction)

Timeline

  • 2026-09-11: disclosed: CVE-2026-89606 published
  • 2026-09-14: patched: Fix committed to stable kernel branches
  • 2026-07-15: other: Patch authored by Yichong Chen

References

Related threats