{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89557","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.724Z","datePublished":"2026-09-11T19:44:29.857Z","dateUpdated":"2026-09-14T12:00:58.984Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:00:58.984Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmd: do overflow check for sb->bblog_shift in super_1_load()\n\nIn super_1_load(), sb->bblog_shift is an __u8 type value loaded from on-\ndisk superblock. It is used for badblocks API badblocks_set() by the\nfollowing sequence,\n\n 1930   rdev->badblocks.shift = sb->bblog_shift;\n 1931   for (i = 0 ; i < (sectors << (9-3)) ; i++, bbp++) {\n 1932           u64 bb = le64_to_cpu(*bbp);\n 1933           int count = bb & (0x3ff);\n 1934           u64 sector = bb >> 10;\n 1935           sector <<= sb->bblog_shift;\n 1936           count <<= sb->bblog_shift;\n 1937           if (bb + 1 == 0)\n 1938                   break;\n 1939           if (!badblocks_set(&rdev->badblocks, sector, count, 1))\n 1940                   return -EINVAL;\n 1941   }\n\nbb->bblog_shit is in range of 0-255, variable sector is 64bit width, for\nan invalid bb->bblog_shit, it is possible to make sector be overflowed\nby the following calculation,\n 1935           sector <<= sb->bblog_shift;\nThen in turn when call badblocks_set() at line 1939 with the invalid\nrdev->badblocks.shift set at line 1930, may result an overflow inside\n_badblocks_clear() in block/badblocks.c.\n\nAlthough there are many places to call badblocks APIs, the non-zero\nshift value is only used in super_1_load(), other places always use 0 as\nthe shift value. Therefore it is unnecessary to do a general shift value\noverflow check inside badblock API, and just check here as the caller.\n\nThis may avoid unnecessary check, make the badblocks API code more simple\nand elegant."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - super_1_load() parses an MD v1 superblock and bad-block log from a local block device via md_import_device() (ADD_NEW_DISK ioctl, sysfs new_dev, udev/mdadm incremental, or boot autodetect), not a network protocol handler such as ksmbd, nfsd, or in-kernel TCP.\nAC:L - The attacker fully controls on-disk bblog_shift (an unchecked __u8, 0-255) and the bad-block log and can set a valid sb_csum; importing that RAID member deterministically overflows sector/count shifts and badblocks rounding with no race or attacker-uncontrollable layout.\nPR:L - md ioctls/sysfs require CAP_SYS_ADMIN, but an unprivileged local user can present a crafted RAID member (udisks loop-setup or equivalent); default udev mdadm --incremental then runs as root and the kernel parses the superblock, so init-namespace root is not required of the attacker.\nUI:N - The attacker attaches and triggers parse of their own crafted image (loop/udisks) themselves; automated udev/mdadm incremental assembly does not require a separate victim to open a file or confirm a prompt.\nS:U - Impact stays in the host kernel MD/badblocks code and that system's storage; this is ordinary same-host kernel memory corruption or denial of service, not a VM escape, IOMMU bypass, or other cross-authority boundary crossing.\nC:H - Overflowed bblog_shift poisons rdev->badblocks.shift and BB_MAKE() encodings in the kernel badblocks table; later badblocks_set/clear/check and raid1/raid10 I/O use those corrupted entries and over-wide shifts, which is kernel memory corruption that can be leveraged for information disclosure.\nI:H - The same overflow writes corrupted badblocks slots (BB_MAKE with wrapped start/len, including all-ones on zero length) and feeds raid1/raid10 narrow_write_error() a bogus 1<<shift block size, giving kernel-state corruption and mis-sized writes exploitable for integrity and control-flow impact.\nA:H - A crafted shift can divide-by-zero in rounddown/roundup, hit BUG() in front_clear(), hard-lock a CPU in _badblocks_set/_badblocks_clear while holding a seqlock with IRQs off, or oops on undefined over-wide shifts, fully denying availability."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/md/md.c"],"versions":[{"version":"2699b67223aca6b1450fc2f72e40fada952afc85","lessThan":"94c820d99a4305d4ded41a97ed37ec7d26c56e7f","status":"affected","versionType":"git"},{"version":"2699b67223aca6b1450fc2f72e40fada952afc85","lessThan":"573fb68105fdc6a127ba6069e58a0d2aff3c9f93","status":"affected","versionType":"git"},{"version":"2699b67223aca6b1450fc2f72e40fada952afc85","lessThan":"323f3a056dbccb39a642ebde642044a680f3a6d6","status":"affected","versionType":"git"},{"version":"2699b67223aca6b1450fc2f72e40fada952afc85","lessThan":"0a03f9541c06fda64301dcf94f376f07ce2cc396","status":"affected","versionType":"git"},{"version":"2699b67223aca6b1450fc2f72e40fada952afc85","lessThan":"75d15738fd33a782606d0dc80cfeff47edf2ddd8","status":"affected","versionType":"git"},{"version":"2699b67223aca6b1450fc2f72e40fada952afc85","lessThan":"3b097416b4cff77285c1f472fc2c4058d8a7554f","status":"affected","versionType":"git"},{"version":"2699b67223aca6b1450fc2f72e40fada952afc85","lessThan":"df7d4d011d5ace20699ea948712f09f9ac08924f","status":"affected","versionType":"git"},{"version":"2699b67223aca6b1450fc2f72e40fada952afc85","lessThan":"35d522bd32462afcf1981dab6da8a9256c26c1e0","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/md/md.c"],"versions":[{"version":"3.1","status":"affected"},{"version":"0","lessThan":"3.1","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.1","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.1","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.1","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.1","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.1","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.1","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.1","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.1","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/94c820d99a4305d4ded41a97ed37ec7d26c56e7f"},{"url":"https://git.kernel.org/stable/c/573fb68105fdc6a127ba6069e58a0d2aff3c9f93"},{"url":"https://git.kernel.org/stable/c/323f3a056dbccb39a642ebde642044a680f3a6d6"},{"url":"https://git.kernel.org/stable/c/0a03f9541c06fda64301dcf94f376f07ce2cc396"},{"url":"https://git.kernel.org/stable/c/75d15738fd33a782606d0dc80cfeff47edf2ddd8"},{"url":"https://git.kernel.org/stable/c/3b097416b4cff77285c1f472fc2c4058d8a7554f"},{"url":"https://git.kernel.org/stable/c/df7d4d011d5ace20699ea948712f09f9ac08924f"},{"url":"https://git.kernel.org/stable/c/35d522bd32462afcf1981dab6da8a9256c26c1e0"}],"title":"md: do overflow check for sb->bblog_shift in super_1_load()","x_generator":{"engine":"bippy-1.2.0"}}}}