---
id: CVE-2026-89557
title: 'md: do overflow check for sb->bblog_shift in super_1_load()'
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  md: do overflow check for sb->bblog_shift in super_1_load()

  In super_1_load(), sb->bblog_shift is an __u8 type value loaded from on-
  disk superblock. It is used for ba…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 2699b67223aca6b1450fc2f72e40fada952afc85 <
    94c820d99a4305d4ded41a97ed37ec7d26c56e7f
  - >-
    Linux >= 2699b67223aca6b1450fc2f72e40fada952afc85 <
    573fb68105fdc6a127ba6069e58a0d2aff3c9f93
  - >-
    Linux >= 2699b67223aca6b1450fc2f72e40fada952afc85 <
    323f3a056dbccb39a642ebde642044a680f3a6d6
  - >-
    Linux >= 2699b67223aca6b1450fc2f72e40fada952afc85 <
    0a03f9541c06fda64301dcf94f376f07ce2cc396
  - >-
    Linux >= 2699b67223aca6b1450fc2f72e40fada952afc85 <
    75d15738fd33a782606d0dc80cfeff47edf2ddd8
  - >-
    Linux >= 2699b67223aca6b1450fc2f72e40fada952afc85 <
    3b097416b4cff77285c1f472fc2c4058d8a7554f
  - >-
    Linux >= 2699b67223aca6b1450fc2f72e40fada952afc85 <
    df7d4d011d5ace20699ea948712f09f9ac08924f
  - >-
    Linux >= 2699b67223aca6b1450fc2f72e40fada952afc85 <
    35d522bd32462afcf1981dab6da8a9256c26c1e0
  - Linux 3.1
published: '2026-09-11'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T12:00:58.984Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-89557'
references:
  - url: 'https://git.kernel.org/stable/c/94c820d99a4305d4ded41a97ed37ec7d26c56e7f'
  - url: 'https://git.kernel.org/stable/c/573fb68105fdc6a127ba6069e58a0d2aff3c9f93'
  - url: 'https://git.kernel.org/stable/c/323f3a056dbccb39a642ebde642044a680f3a6d6'
  - url: 'https://git.kernel.org/stable/c/0a03f9541c06fda64301dcf94f376f07ce2cc396'
  - url: 'https://git.kernel.org/stable/c/75d15738fd33a782606d0dc80cfeff47edf2ddd8'
  - url: 'https://git.kernel.org/stable/c/3b097416b4cff77285c1f472fc2c4058d8a7554f'
  - url: 'https://git.kernel.org/stable/c/df7d4d011d5ace20699ea948712f09f9ac08924f'
  - url: 'https://git.kernel.org/stable/c/35d522bd32462afcf1981dab6da8a9256c26c1e0'
tags:
  - cve.org
epss: 0.00164
epssPercentile: 0.06017
ingestedAt: '2026-09-14T15:23:07.451Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

md: do overflow check for sb->bblog_shift in super_1_load()

In super_1_load(), sb->bblog_shift is an __u8 type value loaded from on-
disk superblock. It is used for badblocks API badblocks_set() by the
following sequence,

 1930   rdev->badblocks.shift = sb->bblog_shift;
 1931   for (i = 0 ; i < (sectors << (9-3)) ; i++, bbp++) {
 1932           u64 bb = le64_to_cpu(*bbp);
 1933           int count = bb & (0x3ff);
 1934           u64 sector = bb >> 10;
 1935           sector <<= sb->bblog_shift;
 1936           count <<= sb->bblog_shift;
 1937           if (bb + 1 == 0)
 1938                   break;
 1939           if (!badblocks_set(&rdev->badblocks, sector, count, 1))
 1940                   return -EINVAL;
 1941   }

bb->bblog_shit is in range of 0-255, variable sector is 64bit width, for
an invalid bb->bblog_shit, it is possible to make sector be overflowed
by the following calculation,
 1935           sector <<= sb->bblog_shift;
Then in turn when call badblocks_set() at line 1939 with the invalid
rdev->badblocks.shift set at line 1930, may result an overflow inside
_badblocks_clear() in block/badblocks.c.

Although there are many places to call badblocks APIs, the non-zero
shift value is only used in super_1_load(), other places always use 0 as
the shift value. Therefore it is unnecessary to do a general shift value
overflow check inside badblock API, and just check here as the caller.

This may avoid unnecessary check, make the badblocks API code more simple
and elegant.

## Affected

- `Linux >= 2699b67223aca6b1450fc2f72e40fada952afc85 < 94c820d99a4305d4ded41a97ed37ec7d26c56e7f`
- `Linux >= 2699b67223aca6b1450fc2f72e40fada952afc85 < 573fb68105fdc6a127ba6069e58a0d2aff3c9f93`
- `Linux >= 2699b67223aca6b1450fc2f72e40fada952afc85 < 323f3a056dbccb39a642ebde642044a680f3a6d6`
- `Linux >= 2699b67223aca6b1450fc2f72e40fada952afc85 < 0a03f9541c06fda64301dcf94f376f07ce2cc396`
- `Linux >= 2699b67223aca6b1450fc2f72e40fada952afc85 < 75d15738fd33a782606d0dc80cfeff47edf2ddd8`
- `Linux >= 2699b67223aca6b1450fc2f72e40fada952afc85 < 3b097416b4cff77285c1f472fc2c4058d8a7554f`
- `Linux >= 2699b67223aca6b1450fc2f72e40fada952afc85 < df7d4d011d5ace20699ea948712f09f9ac08924f`
- `Linux >= 2699b67223aca6b1450fc2f72e40fada952afc85 < 35d522bd32462afcf1981dab6da8a9256c26c1e0`
- `Linux 3.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
