io_uring/rw: end write accounting from ->ki_complete

Summary

CVECVE-2026-97619
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-09-25 11:17:16 UTC
Updated2026-09-25 11:17:16 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: io_uring/rw: end write accounting from ->ki_complete Commit b000145e9907 moved both the fsnotify calls and the write accounting out of the kiocb completion handler and into the io_req_rw_complete() task_work. However, only the fsnotify part actually needed to move as it may sleep. Ending the write accounting is just a percpu_up_read() on the superblock writers sem. Deferring it is a problem, because it makes dropping SB_FREEZE_WRITE protection depend on the ring owner getting to running task_work. But the task may be blocked in freeze_super(), causing it to never get to that: task io-wq worker -------------------------------------------------------------- io_write() io_kiocb_start_write() (takes sb_writers, hidden from lockdep by __sb_writers_release) write_iter() -> -EIOCBQUEUED ioctl(FS_IOC_SHUTDOWN) bdev_freeze() freeze_super() percpu_down_write() <- waits for the reader above io_write() kiocb_start_write() percpu_down_read() <- queued behind the writer <bio completes> io_complete_rw() queues io_req_rw_complete() <- never runs, task is in D state End the write from io_complete_rw() instead, and leave only the fsnotify calls in task_work.

Risk And Classification

EPSS: 0.001980000 probability, percentile 0.085890000 (date 2026-09-27)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected b000145e9907809406d8164c3b2b8861d95aecd1 cc580cee4dfa2ec9099c30ecbd4d804cbb996432 git Not specified
CNA Linux Linux affected b000145e9907809406d8164c3b2b8861d95aecd1 055d43a1233edbd80e558889258105ce63051bcd git Not specified
CNA Linux Linux affected b000145e9907809406d8164c3b2b8861d95aecd1 796aa0547557e63338657ed1c487906f9fac4c73 git Not specified
CNA Linux Linux affected ea2e6286e3e89a115ae554e20ba9aec2b2e1ddff git Not specified
CNA Linux Linux affected 89a410dbd0f159ddd308f19d6eb682fc753e4771 git Not specified
CNA Linux Linux affected 2a853c206e553dd9c0a55c22858fd6a446d93e15 git Not specified
CNA Linux Linux affected 5.10.165 5.11 semver Not specified
CNA Linux Linux affected 5.15.90 5.16 semver Not specified
CNA Linux Linux affected 6.0.3 6.1 semver Not specified
CNA Linux Linux affected 6.1 Not specified
CNA Linux Linux unaffected 6.1 semver Not specified
CNA Linux Linux unaffected 6.18.53 6.18.* semver Not specified
CNA Linux Linux unaffected 7.2.7 7.2.* semver Not specified
CNA Linux Linux unaffected 7.3-rc3 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/cc580cee4dfa2ec9099c30ecbd4d804cbb996432 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/796aa0547557e63338657ed1c487906f9fac4c73 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/055d43a1233edbd80e558889258105ce63051bcd 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report