9.8

CVE-2026-89558

md/raid10: fix still_degraded being inverted in raid10_sync_request()

In the Linux kernel, the following vulnerability has been resolved:

md/raid10: fix still_degraded being inverted in raid10_sync_request()

Commit fe6a19d40ceb ("md/md-bitmap: merge md_bitmap_start_sync() into
bitmap_operations") converted still_degraded from int to bool, but
inverted the assignment in the loop that checks whether the array will
still be degraded after the current device is recovered:
"still_degraded = 1" became "still_degraded = false".

As a result, recovering a device while another mirror is still missing
calls md_bitmap_start_sync() with degraded == false, which clears bitmap
bits that the still-missing device needs.  When that device is re-added,
its bitmap-based recovery finds the bits already cleared and skips every
region written while the array was degraded, so it is marked In_sync
while holding stale data: silent corruption.

Reproducer (raid10 near=2, 4 disks, internal bitmap):
 - fail and remove one disk of each mirror pair
 - write to the degraded array
 - re-add both disks and let recovery finish
 - "check" reports mismatch_cnt=262272 after 256 MiB of degraded
   writes and file contents differ; the second disk's "recovery"
   completes in milliseconds because everything is skipped

The same conversion in raid1 got it right (still_degraded = true).
Restore the correct value.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version fe6a19d40ceb44281905485f56dda715e3214e0e
Version < 9bb8da6ecb330a5b1ac9b96f1e55f134a7aef1d4
Status affected
Version fe6a19d40ceb44281905485f56dda715e3214e0e
Version < 0efabe6229dc683dbf6eeebd0f9fddc7971ed420
Status affected
Version fe6a19d40ceb44281905485f56dda715e3214e0e
Version < 00449d752bee9c8787f42ea1bf533a9fb17f9b6b
Status affected
Version fe6a19d40ceb44281905485f56dda715e3214e0e
Version < 47f1441b281decde6954a2fa82b4131637d685ac
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.12
Status affected
Version 0
Version < 6.12
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.63% 0.481
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/9bb8da6ecb330a5b1ac9b96f1e55f134a7aef1d4
https://git.kernel.org/stable/c/0efabe6229dc683dbf6eeebd0f9fddc7971ed420
https://git.kernel.org/stable/c/00449d752bee9c8787f42ea1bf533a9fb17f9b6b
https://git.kernel.org/stable/c/47f1441b281decde6954a2fa82b4131637d685ac