PT-2026-98559 · Linux · Linux

CVE-2026-97619

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
io uring/rw: end write accounting from ->ki complete
Commit b000145e9907 moved both the fsnotify calls and the write accounting out of the kiocb completion handler and into the io req rw complete() task work. However, only the fsnotify part actually needed to move as it may sleep. Ending the write accounting is just a percpu up read() on the superblock writers sem.
Deferring it is a problem, because it makes dropping SB FREEZE WRITE protection depend on the ring owner getting to running task work. But the task may be blocked in freeze super(), causing it to never get to that:

task io-wq worker

io write() io kiocb start write() (takes sb writers, hidden from lockdep by sb writers release) write iter() -> -EIOCBQUEUED ioctl(FS IOC SHUTDOWN) bdev freeze() freeze super() percpu down write() <- waits for the reader above io write() kiocb start write() percpu down read() <- queued behind the writer io complete rw() queues io req rw complete() <- never runs, task is in D state
End the write from io complete rw() instead, and leave only the fsnotify calls in task work.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-97619

Affected Products

Linux