CVE-2026-89169: Debian Live-Boot

Medium severity, CVSS 4.1. EPSS: 0.1% chance of exploitation in the next 30 days.

live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.

Affected products

Published 2026-09-11. Last modified 2026-09-22.