{
  "threat_severity" : "Moderate",
  "public_date" : "2026-09-11T19:44:30Z",
  "bugzilla" : {
    "description" : "kernel: Linux kernel md/raid10: Silent data corruption due to inverted degraded state during array recovery",
    "id" : "2532221",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2532221"
  },
  "cvss3" : {
    "cvss3_base_score" : "4.4",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N",
    "status" : "draft"
  },
  "cwe" : "CWE-480",
  "details" : [ "In the Linux kernel, the following vulnerability has been resolved:\nmd/raid10: fix still_degraded being inverted in raid10_sync_request()\nCommit fe6a19d40ceb (\"md/md-bitmap: merge md_bitmap_start_sync() into\nbitmap_operations\") converted still_degraded from int to bool, but\ninverted the assignment in the loop that checks whether the array will\nstill be degraded after the current device is recovered:\n\"still_degraded = 1\" became \"still_degraded = false\".\nAs a result, recovering a device while another mirror is still missing\ncalls md_bitmap_start_sync() with degraded == false, which clears bitmap\nbits that the still-missing device needs.  When that device is re-added,\nits bitmap-based recovery finds the bits already cleared and skips every\nregion written while the array was degraded, so it is marked In_sync\nwhile holding stale data: silent corruption.\nReproducer (raid10 near=2, 4 disks, internal bitmap):\n- fail and remove one disk of each mirror pair\n- write to the degraded array\n- re-add both disks and let recovery finish\n- \"check\" reports mismatch_cnt=262272 after 256 MiB of degraded\nwrites and file contents differ; the second disk's \"recovery\"\ncompletes in milliseconds because everything is skipped\nThe same conversion in raid1 got it right (still_degraded = true).\nRestore the correct value.", "A flaw was found in the Linux kernel's md/raid10 (RAID10) driver. This vulnerability occurs when a RAID10 array is in a degraded state and a device is being recovered while another mirror is still missing. Due to an inverted boolean value, the system incorrectly clears necessary bitmap bits, causing subsequent recovery operations to skip regions with stale data. This can lead to silent data corruption on the re-added device, impacting data integrity." ],
  "package_state" : [ {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift/ose-rhel-coreos-8",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift/ose-rhel-coreos-9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-89558\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-89558\nhttps://git.kernel.org/stable/c/00449d752bee9c8787f42ea1bf533a9fb17f9b6b\nhttps://git.kernel.org/stable/c/0efabe6229dc683dbf6eeebd0f9fddc7971ed420\nhttps://git.kernel.org/stable/c/47f1441b281decde6954a2fa82b4131637d685ac\nhttps://git.kernel.org/stable/c/9bb8da6ecb330a5b1ac9b96f1e55f134a7aef1d4" ],
  "name" : "CVE-2026-89558",
  "csaw" : false
}