PT-2026-98559 · Linux · Linux
CVE-2026-97619
·
Published
2026-09-25
·
Updated
2026-09-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
io uring/rw: end write accounting from ->ki complete
Commit b000145e9907 moved both the fsnotify calls and the write
accounting out of the kiocb completion handler and into the
io req rw complete() task work. However, only the fsnotify part actually
needed to move as it may sleep. Ending the write accounting is just a
percpu up read() on the superblock writers sem.
Deferring it is a problem, because it makes dropping SB FREEZE WRITE
protection depend on the ring owner getting to running task work. But
the task may be blocked in freeze super(), causing it to never get to
that:
task io-wq worker
io write()
io kiocb start write() (takes sb writers, hidden from
lockdep by sb writers release)
write iter() -> -EIOCBQUEUED
ioctl(FS IOC SHUTDOWN)
bdev freeze()
freeze super()
percpu down write() <- waits for the reader above
io write()
kiocb start write()
percpu down read() <- queued
behind the
writer
io complete rw()
queues io req rw complete() <- never runs, task is in D state
End the write from io complete rw() instead, and leave only the fsnotify
calls in task work.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux