Always-Incorrect Control Flow Implementation in Linux kernel - CVE-2026-89558
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause silent data corruption.
The vulnerability exists due to incorrect control flow implementation in raid10_sync_request() in drivers/md/raid10.c when recovering RAID10 devices while another mirror remains missing. A local privileged user can write to a degraded RAID10 array and re-add affected devices to cause silent data corruption.
Exploitation requires bitmap-based recovery.