CVE-2026-97619

Summary

In the Linux kernel, the following vulnerability has been resolved:

io_uring/rw: end write accounting from ->ki_complete

Commit b000145e9907 moved both the fsnotify calls and the write accounting out of the kiocb completion handler and into the io_req_rw_complete() task_work. However, only the fsnotify part actually needed to move as it may sleep. Ending the write accounting is just a percpu_up_read() on the superblock writers sem.

Deferring it is a problem, because it makes dropping SB_FREEZE_WRITE protection depend on the ring owner getting to running task_work. But the task may be blocked in freeze_super(), causing it to never get to that:

task io-wq worker

io_write() io_kiocb_start_write() (takes sb_writers, hidden from lockdep by __sb_writers_release) write_iter() -> -EIOCBQUEUED ioctl(FS_IOC_SHUTDOWN) bdev_freeze() freeze_super() percpu_down_write() <- waits for the reader above io_write() kiocb_start_write() percpu_down_read() <- queued behind the writer <bio completes> io_complete_rw() queues io_req_rw_complete() <- never runs, task is in D state

End the write from io_complete_rw() instead, and leave only the fsnotify calls in task_work.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxb000145e9907809406d8164c3b2b8861d95aecd1 < cc580cee4dfa2ec9099c30ecbd4d804cbb996432affected
LinuxLinuxb000145e9907809406d8164c3b2b8861d95aecd1 < 055d43a1233edbd80e558889258105ce63051bcdaffected
LinuxLinuxb000145e9907809406d8164c3b2b8861d95aecd1 < 796aa0547557e63338657ed1c487906f9fac4c73affected
LinuxLinuxea2e6286e3e89a115ae554e20ba9aec2b2e1ddffaffected
LinuxLinux89a410dbd0f159ddd308f19d6eb682fc753e4771affected
LinuxLinux2a853c206e553dd9c0a55c22858fd6a446d93e15affected
LinuxLinux5.10.165 < 5.11affected
LinuxLinux5.15.90 < 5.16affected
LinuxLinux6.0.3 < 6.1affected
LinuxLinux6.1affected
LinuxLinux0 < 6.1unaffected
LinuxLinux6.18.53 <= 6.18.*unaffected
LinuxLinux7.2.7 <= 7.2.*unaffected
LinuxLinux7.3-rc3 <= *unaffected

Weaknesses

References