« Volver al listado

CVE-2026-97619

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

io_uring/rw: end write accounting from ->ki_complete

Commit b000145e9907 moved both the fsnotify calls and the write accounting out of the kiocb completion handler and into the io_req_rw_complete() task_work. However, only the fsnotify part actually needed to move as it may sleep. Ending the write accounting is just a percpu_up_read() on the superblock writers sem.

Deferring it is a problem, because it makes dropping SB_FREEZE_WRITE protection depend on the ring owner getting to running task_work. But the task may be blocked in freeze_super(), causing it to never get to that:

Leer descripción completaMostrar menos

End the write from io_complete_rw() instead, and leave only the fsnotify calls in task_work.

Detalles técnicos trazas, registros y código del informe original
  task                             io-wq worker
  --------------------------------------------------------------
  io_write()
    io_kiocb_start_write()         (takes sb_writers, hidden from
                                    lockdep by __sb_writers_release)
    write_iter() -> -EIOCBQUEUED
  ioctl(FS_IOC_SHUTDOWN)
    bdev_freeze()
      freeze_super()
        percpu_down_write()        <- waits for the reader above
                                   io_write()
                                     kiocb_start_write()
                                       percpu_down_read()  <- queued
                                                              behind the
                                                              writer
  <bio completes>
    io_complete_rw()
      queues io_req_rw_complete()  <- never runs, task is in D state

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-97619",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "b000145e9907809406d8164c3b2b8861d95aecd1",
              "lessThan": "696459029f3b65c070c91b729478475582f1dcdf",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b000145e9907809406d8164c3b2b8861d95aecd1",
              "lessThan": "cc580cee4dfa2ec9099c30ecbd4d804cbb996432",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b000145e9907809406d8164c3b2b8861d95aecd1",
              "lessThan": "055d43a1233edbd80e558889258105ce63051bcd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b000145e9907809406d8164c3b2b8861d95aecd1",
              "lessThan": "796aa0547557e63338657ed1c487906f9fac4c73",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ea2e6286e3e89a115ae554e20ba9aec2b2e1ddff",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "89a410dbd0f159ddd308f19d6eb682fc753e4771",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2a853c206e553dd9c0a55c22858fd6a446d93e15",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.10.165",
              "lessThan": "5.11",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.15.90",
              "lessThan": "5.16",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.0.3",
              "lessThan": "6.1",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "io_uring/rw.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.1"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.1",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc3",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "io_uring/rw.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:16.117",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/055d43a1233edbd80e558889258105ce63051bcd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/696459029f3b65c070c91b729478475582f1dcdf",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/796aa0547557e63338657ed1c487906f9fac4c73",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cc580cee4dfa2ec9099c30ecbd4d804cbb996432",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring/rw: end write accounting from ->ki_complete\n\nCommit b000145e9907 moved both the fsnotify calls and the write\naccounting out of the kiocb completion handler and into the\nio_req_rw_complete() task_work. However, only the fsnotify part actually\nneeded to move as it may sleep. Ending the write accounting is just a\npercpu_up_read() on the superblock writers sem.\n\nDeferring it is a problem, because it makes dropping SB_FREEZE_WRITE\nprotection depend on the ring owner getting to running task_work. But\nthe task may be blocked in freeze_super(), causing it to never get to\nthat:\n\n  task                             io-wq worker\n  --------------------------------------------------------------\n  io_write()\n    io_kiocb_start_write()         (takes sb_writers, hidden from\n                                    lockdep by __sb_writers_release)\n    write_iter() -> -EIOCBQUEUED\n  ioctl(FS_IOC_SHUTDOWN)\n    bdev_freeze()\n      freeze_super()\n        percpu_down_write()        <- waits for the reader above\n                                   io_write()\n                                     kiocb_start_write()\n                                       percpu_down_read()  <- queued\n                                                              behind the\n                                                              writer\n  <bio completes>\n    io_complete_rw()\n      queues io_req_rw_complete()  <- never runs, task is in D state\n\nEnd the write from io_complete_rw() instead, and leave only the fsnotify\ncalls in task_work."
    }
  ],
  "lastModified": "2026-10-03T11:18:08.137",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}