PT-2026-98559 · Linux · Linux

CVE-2026-97619

·

Publicado

2026-09-25

·

Atualizado

2026-09-25

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
io uring/rw: end write accounting from ->ki complete
Commit b000145e9907 moved both the fsnotify calls and the write accounting out of the kiocb completion handler and into the io req rw complete() task work. However, only the fsnotify part actually needed to move as it may sleep. Ending the write accounting is just a percpu up read() on the superblock writers sem.
Deferring it is a problem, because it makes dropping SB FREEZE WRITE protection depend on the ring owner getting to running task work. But the task may be blocked in freeze super(), causing it to never get to that:

task io-wq worker

io write() io kiocb start write() (takes sb writers, hidden from lockdep by sb writers release) write iter() -> -EIOCBQUEUED ioctl(FS IOC SHUTDOWN) bdev freeze() freeze super() percpu down write() <- waits for the reader above io write() kiocb start write() percpu down read() <- queued behind the writer io complete rw() queues io req rw complete() <- never runs, task is in D state
End the write from io complete rw() instead, and leave only the fsnotify calls in task work.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-97619

Produtos afetados

Linux