← All Advisories

CVE-2026-97619

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97619

Key Details

CVECVE-2026-97619
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

io_uring/rw: end write accounting from ->ki_complete

Commit b000145e9907 moved both the fsnotify calls and the write

accounting out of the kiocb completion handler and into the

io_req_rw_complete() task_work. However, only the fsnotify part actually

needed to move as it may sleep. Ending the write accounting is just a

percpu_up_read() on the superblock writers sem.

Deferring it is a problem, because it makes dropping SB_FREEZE_WRITE

protection depend on the ring owner getting to running task_work. But

the task may be blocked in freeze_super(), causing it to never get to

that:

task io-wq worker

--------------------------------------------------------------

io_write()

io_kiocb_start_write() (takes sb_writers, hidden from

lockdep by __sb_writers_release)

write_iter() -> -EIOCBQUEUED

ioctl(FS_IOC_SHUTDOWN)

bdev_freeze()

freeze_super()

percpu_down_write() <- waits for the reader above

io_write()

kiocb_start_write()

percpu_down_read() <- queued

behind the

writer

<bio completes>

io_complete_rw()

queues io_req_rw_complete() <- never runs, task is in D state

End the write from io_complete_rw() instead, and leave only the fsnotify

calls in task_work. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97619
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97619