Bypass Vulnerability in live-boot Product by Debian
CVE-2026-89169

4.1MEDIUM

Key Information:

Vendor

Debian

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-89169?

In live-boot version ff8867c, a security bypass vulnerability exists that allows attackers to circumvent the dm-verity-enforce-roothash-signature protection mechanism. This occurs when the crucial .verity file is absent. This lack of validation can potentially expose systems to unauthorized modifications, posing significant security risks.

Affected Version(s)

live-boot ff8867c4e2d62e497cb895b15b7d6d518d5adff1

References

CVSS V4

Score:
4.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.