-
CVE-2026-97619
- EPSS 0.2%
- Veröffentlicht 25.09.2026 10:22:25
- Zuletzt bearbeitet 03.10.2026 11:18:08
- Erkennungen
io_uring/rw: end write accounting from ->ki_complete
In the Linux kernel, the following vulnerability has been resolved:
io_uring/rw: end write accounting from ->ki_complete
Commit b000145e9907 moved both the fsnotify calls and the write
accounting out of the kiocb completion handler and into the
io_req_rw_complete() task_work. However, only the fsnotify part actually
needed to move as it may sleep. Ending the write accounting is just a
percpu_up_read() on the superblock writers sem.
Deferring it is a problem, because it makes dropping SB_FREEZE_WRITE
protection depend on the ring owner getting to running task_work. But
the task may be blocked in freeze_super(), causing it to never get to
that:
task io-wq worker
--------------------------------------------------------------
io_write()
io_kiocb_start_write() (takes sb_writers, hidden from
lockdep by __sb_writers_release)
write_iter() -> -EIOCBQUEUED
ioctl(FS_IOC_SHUTDOWN)
bdev_freeze()
freeze_super()
percpu_down_write() <- waits for the reader above
io_write()
kiocb_start_write()
percpu_down_read() <- queued
behind the
writer
<bio completes>
io_complete_rw()
queues io_req_rw_complete() <- never runs, task is in D state
End the write from io_complete_rw() instead, and leave only the fsnotify
calls in task_work.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
b000145e9907809406d8164c3b2b8861d95aecd1
Version <
696459029f3b65c070c91b729478475582f1dcdf
Status
affected
Version
b000145e9907809406d8164c3b2b8861d95aecd1
Version <
cc580cee4dfa2ec9099c30ecbd4d804cbb996432
Status
affected
Version
b000145e9907809406d8164c3b2b8861d95aecd1
Version <
055d43a1233edbd80e558889258105ce63051bcd
Status
affected
Version
b000145e9907809406d8164c3b2b8861d95aecd1
Version <
796aa0547557e63338657ed1c487906f9fac4c73
Status
affected
Version
ea2e6286e3e89a115ae554e20ba9aec2b2e1ddff
Status
affected
Version
89a410dbd0f159ddd308f19d6eb682fc753e4771
Status
affected
Version
2a853c206e553dd9c0a55c22858fd6a446d93e15
Status
affected
Version
5.10.165
Version <
5.11
Status
affected
Version
5.15.90
Version <
5.16
Status
affected
Version
6.0.3
Version <
6.1
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.1
Status
affected
Version
0
Version <
6.1
Status
unaffected
Version <=
6.12.*
Version
6.12.112
Status
unaffected
Version <=
6.18.*
Version
6.18.53
Status
unaffected
Version <=
7.2.*
Version
7.2.7
Status
unaffected
Version <=
*
Version
7.3-rc3
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.086 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/cc580cee4dfa2ec9099c30ecbd4d804cbb996432
https://git.kernel.org/stable/c/055d43a1233edbd80e558889258105ce63051bcd
https://git.kernel.org/stable/c/796aa0547557e63338657ed1c487906f9fac4c73
https://git.kernel.org/stable/c/696459029f3b65c070c91b729478475582f1dcdf