Junglewise Threat Intelligence

CVE-2026-89607: Linux kernel ecryptfs out-of-bounds write in parse_tag_3_packet

CVE-2026-89607 · Severity: high · CVSS 7.8 · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's ecryptfs encryption layer contains a buffer overflow vulnerability in how it processes encrypted passphrase packets. An attacker with the ability to supply a specially crafted encrypted key file can trigger out-of-bounds memory writes, potentially leading to privilege escalation, data corruption, or system crashes.

Technical details

The vulnerability exists in parse_tag_3_packet() and decrypt_passphrase_encrypted_session_key() functions, which process ecryptfs Tag 3 packets without properly validating the encrypted_key_size field against ECRYPTFS_MAX_KEY_BYTES (64 bytes). When encrypted_key_size exceeds 64 bytes, two out-of-bounds writes occur: (1) crypto_skcipher_decrypt() writes beyond the 64-byte decrypted_key buffer into the parent ecryptfs_auth_tok struct, and (2) memcpy() subsequently writes into crypt_stat->key[64], corrupting critical kernel data structures (root_iv, keysig_list, mutexes). The vulnerability is exploitable only with AES-192 cipher (code 0x08), which allows the kernel to accept oversized keys. A fix has been implemented that bounds encrypted_key_size against ECRYPTFS_MAX_KEY_BYTES, mirroring the existing validation in the PKI decryption path.

Affected products

  • Linux Linux kernel multiple versions prior to fix

Timeline

  • 2026-09-11: disclosed
  • 2026-09-11: patched: Fix applied: validate encrypted_key_size against ECRYPTFS_MAX_KEY_BYTES in parse_tag_3_packet()

Related threats