9.8
CVE-2026-89558
- EPSS 0.63%
- Veröffentlicht 11.09.2026 19:44:30
- Zuletzt bearbeitet 13.09.2026 07:17:21
- Erkennungen
md/raid10: fix still_degraded being inverted in raid10_sync_request()
In the Linux kernel, the following vulnerability has been resolved:
md/raid10: fix still_degraded being inverted in raid10_sync_request()
Commit fe6a19d40ceb ("md/md-bitmap: merge md_bitmap_start_sync() into
bitmap_operations") converted still_degraded from int to bool, but
inverted the assignment in the loop that checks whether the array will
still be degraded after the current device is recovered:
"still_degraded = 1" became "still_degraded = false".
As a result, recovering a device while another mirror is still missing
calls md_bitmap_start_sync() with degraded == false, which clears bitmap
bits that the still-missing device needs. When that device is re-added,
its bitmap-based recovery finds the bits already cleared and skips every
region written while the array was degraded, so it is marked In_sync
while holding stale data: silent corruption.
Reproducer (raid10 near=2, 4 disks, internal bitmap):
- fail and remove one disk of each mirror pair
- write to the degraded array
- re-add both disks and let recovery finish
- "check" reports mismatch_cnt=262272 after 256 MiB of degraded
writes and file contents differ; the second disk's "recovery"
completes in milliseconds because everything is skipped
The same conversion in raid1 got it right (still_degraded = true).
Restore the correct value.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
fe6a19d40ceb44281905485f56dda715e3214e0e
Version <
9bb8da6ecb330a5b1ac9b96f1e55f134a7aef1d4
Status
affected
Version
fe6a19d40ceb44281905485f56dda715e3214e0e
Version <
0efabe6229dc683dbf6eeebd0f9fddc7971ed420
Status
affected
Version
fe6a19d40ceb44281905485f56dda715e3214e0e
Version <
00449d752bee9c8787f42ea1bf533a9fb17f9b6b
Status
affected
Version
fe6a19d40ceb44281905485f56dda715e3214e0e
Version <
47f1441b281decde6954a2fa82b4131637d685ac
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.12
Status
affected
Version
0
Version <
6.12
Status
unaffected
Version <=
6.12.*
Version
6.12.109
Status
unaffected
Version <=
6.18.*
Version
6.18.50
Status
unaffected
Version <=
7.2.*
Version
7.2.4
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.63% | 0.481 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/9bb8da6ecb330a5b1ac9b96f1e55f134a7aef1d4
https://git.kernel.org/stable/c/0efabe6229dc683dbf6eeebd0f9fddc7971ed420
https://git.kernel.org/stable/c/00449d752bee9c8787f42ea1bf533a9fb17f9b6b
https://git.kernel.org/stable/c/47f1441b281decde6954a2fa82b4131637d685ac