CVE-2026-89558
In the Linux kernel, the following vulnerability has been resolved:
md/raid10: fix stilldegraded being inverted in raid10sync_request()
Commit fe6a19d40ceb ("md/md-bitmap: merge mdbitmapstart_sync() into
bitmapoperations") converted stilldegraded from int to bool, but
inverted the assignment in the loop that checks whether the array will
still be degraded after the current device is recovered:
"stilldegraded = 1" became "stilldegraded = false".
As a result, recovering a device while another mirror is still missing
calls mdbitmapstart_sync() with degraded == false, which clears bitmap
bits that the still-missing device needs. When that device is re-added,
its bitmap-based recovery finds the bits already cleared and skips every
region written while the array was degraded, so it is marked In_sync
while holding stale data: silent corruption.
Reproducer (raid10 near=2, 4 disks, internal bitmap):
- fail and remove one disk of each mirror pair
- write to the degraded array
- re-add both disks and let recovery finish
- "check" reports mismatch_cnt=262272 after 256 MiB of degraded
writes and file contents differ; the second disk's "recovery"
completes in milliseconds because everything is skipped
The same conversion in raid1 got it right (still_degraded = true).
Restore the correct value.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/00449d752bee9c8787f42ea1bf533a9fb17f9b6b, https://git.kernel.org/stable/c/0efabe6229dc683dbf6eeebd0f9fddc7971ed420, https://git.kernel.org/stable/c/47f1441b281decde6954a2fa82b4131637d685ac, https://git.kernel.org/stable/c/9bb8da6ecb330a5b1ac9b96f1e55f134a7aef1d4, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89558.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89558, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git