๐Ÿ” CVE Alert

CVE-2026-89169

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.

CWE CWE-347
Vendor debian
Product live-boot
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 11, 2026
Stay Ahead of the Next One

Get instant alerts for debian live-boot

Be the first to know when new unknown vulnerabilities affecting debian live-boot are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Debian / live-boot
ff8867c4e2d62e497cb895b15b7d6d518d5adff1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
bugs.debian.org: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1146422 salsa.debian.org: https://salsa.debian.org/live-team/live-boot/-/blob/ff8867c4e2d62e497cb895b15b7d6d518d5adff1/components/9990-overlay.sh#L112-114