CVE-2026-89606
Received Received - Intake

ecryptfs Tag 70 Packet Size Underflow Vulnerability

Vulnerability report for CVE-2026-89606, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: ecryptfs: reject too-small tag 70 packets ecryptfs_parse_tag_70_packet() subtracts fixed metadata fields from the parsed packet body size to derive the encrypted filename size. A malformed packet with a body smaller than those fixed fields can underflow that size calculation. Reject tag 70 packets before the subtraction unless the body contains the signature, cipher code, and at least one byte of encrypted filename data.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux_kernel ecryptfs *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Linux kernel's ecryptfs module. It involves a flaw in how tag 70 packets are parsed. When processing these packets, the function subtracts fixed metadata fields from the packet body size to determine the encrypted filename size. If the packet body is too small, this calculation can underflow, leading to incorrect processing.

Detection Guidance

This vulnerability is specific to the Linux kernel's ecryptfs module and involves malformed tag 70 packets. Detection requires checking kernel logs for ecryptfs-related errors or parsing network traffic for malformed packets targeting ecryptfs. Use commands like 'dmesg | grep ecryptfs' to check for kernel logs or 'tcpdump -i any -A -e -n port 3310' to monitor network traffic for suspicious packets.

Impact Analysis

This vulnerability could allow an attacker to cause a denial of service or potentially execute arbitrary code by sending a malformed tag 70 packet. It affects systems using ecryptfs for file encryption, potentially leading to system crashes or unauthorized access.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards as it is a low-level kernel issue in ecryptfs related to packet parsing. It may indirectly impact compliance if exploited to access encrypted filenames, potentially violating data confidentiality requirements in regulated environments.

Mitigation Strategies

Update the Linux kernel to the latest patched version to resolve this issue. If immediate patching is not possible, disable the ecryptfs module by running 'modprobe -r ecryptfs' and prevent it from loading at boot with 'echo "blacklist ecryptfs" >> /etc/modprobe.d/disable-ecryptfs.conf'.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89606. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart