CVE-2026-89169

live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.

  • Published Sep 11, 2026
  • CVSS 4.1 medium
  • 0.1% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-89169 at the National Vulnerability Database