CVE-2026-89169: Live-boot vulnerability
Published Sep 11, 2026
·Updated
live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.
Affected Software
1 affected component
live-boot=ff8867c
Event History
Sep 11, 2026
CVE Published
via MITRE·04:44 AM
Data Sourced
via MITRE·04:44 AM
DescriptionWeakness
Frequently Asked Questions
1
Under what condition can the protection be bypassed?
The bypass is possible when the .verity file is missing. In that condition, live-boot ff8867c does not enforce the dm-verity root-hash signature protection mechanism.
2
What should be checked when assessing exposure?
Check whether systems using live-boot ff8867c rely on dm-verity-enforce-roothash-signature and whether the expected .verity file is present. A missing .verity file indicates the condition described for the bypass.