CVE-2026-97619
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/09/2026
Última modificación:
25/09/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
io_uring/rw: end write accounting from ->ki_complete<br />
<br />
Commit b000145e9907 moved both the fsnotify calls and the write<br />
accounting out of the kiocb completion handler and into the<br />
io_req_rw_complete() task_work. However, only the fsnotify part actually<br />
needed to move as it may sleep. Ending the write accounting is just a<br />
percpu_up_read() on the superblock writers sem.<br />
<br />
Deferring it is a problem, because it makes dropping SB_FREEZE_WRITE<br />
protection depend on the ring owner getting to running task_work. But<br />
the task may be blocked in freeze_super(), causing it to never get to<br />
that:<br />
<br />
task io-wq worker<br />
--------------------------------------------------------------<br />
io_write()<br />
io_kiocb_start_write() (takes sb_writers, hidden from<br />
lockdep by __sb_writers_release)<br />
write_iter() -> -EIOCBQUEUED<br />
ioctl(FS_IOC_SHUTDOWN)<br />
bdev_freeze()<br />
freeze_super()<br />
percpu_down_write()


