Junglewise Threat Intelligence

CVE-2026-89577: Linux kernel dm-io error handling logic flaw

CVE-2026-89577 · Severity: info · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A bug in the Linux kernel's device mapper I/O (dm-io) layer caused dm-raid1 (a RAID-1 software implementation) to incorrectly mark storage devices as failed when they returned certain unsupported operation errors. This resulted in unnecessary device failures and potential data availability issues when users accessed storage with unaligned I/O requests. The fix distinguishes between truly-failed I/O errors and unsupported operation errors, preventing false device failures.

Technical details

The vulnerability is a logic error in the dm-io (device mapper I/O) subsystem's error reporting interface. Previously, error codes BLK_STS_NOTSUPP (operation not supported) and BLK_STS_INVAL (invalid operation) were treated identically to true I/O failures, causing dm-raid1 to incorrectly mark a RAID leg (device) as failed. The fix changes dm-io to report two separate error bitmaps: error_bits for true I/O errors and unsup_bits for unsupported/invalid operations. dm-raid1 is then modified to ignore unsupported operation errors when deciding whether to fail a device leg. This manifests when users issue unaligned bio (block I/O) vectors on dm-raid1 configurations. The issue is local to systems running affected kernel versions with dm-raid1 enabled.

Affected products

  • Linux Linux kernel multiple versions (2.6.11 through 7.2.y)

Timeline

  • 2026-09-11: disclosed
  • 2026-09-07: patched

References

Related threats