io_uring/rw: end write accounting from ->ki_complete
Summary
| CVE | CVE-2026-97619 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-25 11:17:16 UTC |
| Updated | 2026-09-25 11:17:16 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: io_uring/rw: end write accounting from ->ki_complete Commit b000145e9907 moved both the fsnotify calls and the write accounting out of the kiocb completion handler and into the io_req_rw_complete() task_work. However, only the fsnotify part actually needed to move as it may sleep. Ending the write accounting is just a percpu_up_read() on the superblock writers sem. Deferring it is a problem, because it makes dropping SB_FREEZE_WRITE protection depend on the ring owner getting to running task_work. But the task may be blocked in freeze_super(), causing it to never get to that: task io-wq worker -------------------------------------------------------------- io_write() io_kiocb_start_write() (takes sb_writers, hidden from lockdep by __sb_writers_release) write_iter() -> -EIOCBQUEUED ioctl(FS_IOC_SHUTDOWN) bdev_freeze() freeze_super() percpu_down_write() <- waits for the reader above io_write() kiocb_start_write() percpu_down_read() <- queued behind the writer <bio completes> io_complete_rw() queues io_req_rw_complete() <- never runs, task is in D state End the write from io_complete_rw() instead, and leave only the fsnotify calls in task_work. |
Risk And Classification
EPSS: 0.001980000 probability, percentile 0.085890000 (date 2026-09-27)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected b000145e9907809406d8164c3b2b8861d95aecd1 cc580cee4dfa2ec9099c30ecbd4d804cbb996432 git | Not specified |
| CNA | Linux | Linux | affected b000145e9907809406d8164c3b2b8861d95aecd1 055d43a1233edbd80e558889258105ce63051bcd git | Not specified |
| CNA | Linux | Linux | affected b000145e9907809406d8164c3b2b8861d95aecd1 796aa0547557e63338657ed1c487906f9fac4c73 git | Not specified |
| CNA | Linux | Linux | affected ea2e6286e3e89a115ae554e20ba9aec2b2e1ddff git | Not specified |
| CNA | Linux | Linux | affected 89a410dbd0f159ddd308f19d6eb682fc753e4771 git | Not specified |
| CNA | Linux | Linux | affected 2a853c206e553dd9c0a55c22858fd6a446d93e15 git | Not specified |
| CNA | Linux | Linux | affected 5.10.165 5.11 semver | Not specified |
| CNA | Linux | Linux | affected 5.15.90 5.16 semver | Not specified |
| CNA | Linux | Linux | affected 6.0.3 6.1 semver | Not specified |
| CNA | Linux | Linux | affected 6.1 | Not specified |
| CNA | Linux | Linux | unaffected 6.1 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.53 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2.7 7.2.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.3-rc3 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/cc580cee4dfa2ec9099c30ecbd4d804cbb996432 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/796aa0547557e63338657ed1c487906f9fac4c73 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/055d43a1233edbd80e558889258105ce63051bcd | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.