{"id":"CVE-2026-89558","title":"kernel: md/raid10: fix still_degraded being inverted in raid10_sync_request() (CVE-2026-89558)","summary":"A flaw was found in the Linux kernel's md/raid10 (RAID10) driver. This vulnerability occurs when a RAID10 array is in a degraded state and a device is being recovered while another mirror is still missing. Due to an inverted boolean value,…","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-480","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","affected":["enterprise_linux 10","enterprise_linux 6","enterprise_linux 9","openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-18","sourceUpdated":"2026-09-18T22:06:53+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89558.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89558.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89558"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532221"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89558"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89558"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89558.mbox"},{"url":"https://git.kernel.org/stable/c/00449d752bee9c8787f42ea1bf533a9fb17f9b6b"},{"url":"https://git.kernel.org/stable/c/0efabe6229dc683dbf6eeebd0f9fddc7971ed420"},{"url":"https://git.kernel.org/stable/c/47f1441b281decde6954a2fa82b4131637d685ac"},{"url":"https://git.kernel.org/stable/c/9bb8da6ecb330a5b1ac9b96f1e55f134a7aef1d4"}],"tags":["csaf","vex","red-hat","cve.org","score-dispute"],"epss":0.00626,"epssPercentile":0.48326,"scores":{"vendor":4.4,"cna":9.8},"ingestedAt":"2026-09-14T15:23:07.474Z","slug":"CVE-2026-89558","body":"## Overview\n\nA flaw was found in the Linux kernel's md/raid10 (RAID10) driver. This vulnerability occurs when a RAID10 array is in a degraded state and a device is being recovered while another mirror is still missing. Due to an inverted boolean value, the system incorrectly clears necessary bitmap bits, causing subsequent recovery operations to skip regions with stale data. This can lead to silent data corruption on the re-added device, impacting data integrity.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89558.json)\n\n**kernel: md/raid10: fix still_degraded being inverted in raid10_sync_request()** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-18.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNot affected:\n\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nOut of support scope","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":208101,"id":"CVE-2026-89558","ts":1789922708806,"field":"cvss","old":"4.4","new":"7"},{"seq":208100,"id":"CVE-2026-89558","ts":1789922708806,"field":"severity","old":"medium","new":"high"},{"seq":202883,"id":"CVE-2026-89558","ts":1789403732798,"field":"cvss","old":"9.8","new":"4.4"},{"seq":202882,"id":"CVE-2026-89558","ts":1789403732798,"field":"severity","old":"critical","new":"medium"},{"seq":197926,"id":"CVE-2026-89558","ts":1789384320981,"field":"cvss","old":"4.4","new":"9.8"},{"seq":197925,"id":"CVE-2026-89558","ts":1789384320981,"field":"severity","old":"medium","new":"critical"},{"seq":183477,"id":"CVE-2026-89558","ts":1789356675527,"field":"cvss","old":"9.8","new":"4.4"},{"seq":183476,"id":"CVE-2026-89558","ts":1789356675527,"field":"severity","old":"critical","new":"medium"},{"seq":153368,"id":"CVE-2026-89558","ts":1789285350235,"field":"cvss","old":null,"new":"9.8"},{"seq":153367,"id":"CVE-2026-89558","ts":1789285350235,"field":"severity","old":"none","new":"critical"},{"seq":147528,"id":"CVE-2026-89558","ts":1789270211262,"field":"cvss","old":null,"new":"4.4"},{"seq":147527,"id":"CVE-2026-89558","ts":1789270211262,"field":"severity","old":"none","new":"medium"},{"seq":109280,"id":"CVE-2026-89558","ts":1789183731259,"field":"cvss","old":null,"new":"4.4"},{"seq":109279,"id":"CVE-2026-89558","ts":1789183731259,"field":"severity","old":"none","new":"medium"}]}