# CVE-2026-89558

## Summary

- **CVE ID:** CVE-2026-89558
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 13, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

md/raid10: fix still_degraded being inverted in raid10_sync_request()

Commit fe6a19d40ceb ("md/md-bitmap: merge md_bitmap_start_sync() into
bitmap_operations") converted still_degraded from int to bool, but
inverted the assignment in the loop that checks whether the array will
still be degraded after the current device is recovered:
"still_degraded = 1" became "still_degraded = false".

As a result, recovering a device while another mirror is still missing
calls md_bitmap_start_sync() with degraded == false, which clears bitmap
bits that the still-missing device needs.  When that device is re-added,
its bitmap-based recovery finds the bits already cleared and skips every
region written while the array was degraded, so it is marked In_sync
while holding stale data: silent corruption.

Reproducer (raid10 near=2, 4 disks, internal bitmap):
 - fail and remove one disk of each mirror pair
 - write to the degraded array
 - re-add both disks and let recovery finish
 - "check" reports mismatch_cnt=262272 after 256 MiB of degraded
   writes and file contents differ; the second disk's "recovery"
   completes in milliseconds because everything is skipped

The same conversion in raid1 got it right (still_degraded = true).
Restore the correct value.

## Affected Products

- Linux — Linux (fe6a19d40ceb44281905485f56dda715e3214e0e)
- Linux — Linux (6.12)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)

## References

- [CNA](https://git.kernel.org/stable/c/9bb8da6ecb330a5b1ac9b96f1e55f134a7aef1d4)
- [CNA](https://git.kernel.org/stable/c/0efabe6229dc683dbf6eeebd0f9fddc7971ed420)
- [CNA](https://git.kernel.org/stable/c/00449d752bee9c8787f42ea1bf533a9fb17f9b6b)
- [CNA](https://git.kernel.org/stable/c/47f1441b281decde6954a2fa82b4131637d685ac)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.63%
- **EPSS Percentile:** 48.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._