CVE-2026-97619
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
io_uring/rw: end write accounting from ->ki_complete
Commit b000145e9907 moved both the fsnotify calls and the write accounting out of the kiocb completion handler and into the io_req_rw_complete() task_work. However, only the fsnotify part actually needed to move as it may sleep. Ending the write accounting is just a percpu_up_read() on the superblock writers sem.
Deferring it is a problem, because it makes dropping SB_FREEZE_WRITE protection depend on the ring owner getting to running task_work. But the task may be blocked in freeze_super(), causing it to never get to that:
task io-wq worker
io_write() io_kiocb_start_write() (takes sb_writers, hidden from lockdep by __sb_writers_release) write_iter() -> -EIOCBQUEUED ioctl(FS_IOC_SHUTDOWN) bdev_freeze() freeze_super() percpu_down_write() <- waits for the reader above io_write() kiocb_start_write() percpu_down_read() <- queued behind the writer <bio completes> io_complete_rw() queues io_req_rw_complete() <- never runs, task is in D state
End the write from io_complete_rw() instead, and leave only the fsnotify calls in task_work.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | b000145e9907809406d8164c3b2b8861d95aecd1 < cc580cee4dfa2ec9099c30ecbd4d804cbb996432 | affected |
| Linux | Linux | b000145e9907809406d8164c3b2b8861d95aecd1 < 055d43a1233edbd80e558889258105ce63051bcd | affected |
| Linux | Linux | b000145e9907809406d8164c3b2b8861d95aecd1 < 796aa0547557e63338657ed1c487906f9fac4c73 | affected |
| Linux | Linux | ea2e6286e3e89a115ae554e20ba9aec2b2e1ddff | affected |
| Linux | Linux | 89a410dbd0f159ddd308f19d6eb682fc753e4771 | affected |
| Linux | Linux | 2a853c206e553dd9c0a55c22858fd6a446d93e15 | affected |
| Linux | Linux | 5.10.165 < 5.11 | affected |
| Linux | Linux | 5.15.90 < 5.16 | affected |
| Linux | Linux | 6.0.3 < 6.1 | affected |
| Linux | Linux | 6.1 | affected |
| Linux | Linux | 0 < 6.1 | unaffected |
| Linux | Linux | 6.18.53 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.7 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc3 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/cc580cee4dfa2ec9099c30ecbd4d804cbb996432
- https://git.kernel.org/stable/c/055d43a1233edbd80e558889258105ce63051bcd
- https://git.kernel.org/stable/c/796aa0547557e63338657ed1c487906f9fac4c73
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.