{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "b000145e9907809406d8164c3b2b8861d95aecd1"
            },
            {
              "fixed": "cc580cee4dfa2ec9099c30ecbd4d804cbb996432"
            },
            {
              "fixed": "055d43a1233edbd80e558889258105ce63051bcd"
            },
            {
              "fixed": "796aa0547557e63338657ed1c487906f9fac4c73"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "last_affected": "ea2e6286e3e89a115ae554e20ba9aec2b2e1ddff"
            },
            {
              "last_affected": "89a410dbd0f159ddd308f19d6eb682fc753e4771"
            },
            {
              "last_affected": "2a853c206e553dd9c0a55c22858fd6a446d93e15"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "5.10.165"
            },
            {
              "fixed": "5.11"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "5.15.90"
            },
            {
              "fixed": "5.16"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "6.0.3"
            },
            {
              "fixed": "6.1"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "6.1.0"
            },
            {
              "fixed": "6.18.53"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.2.7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97619.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring/rw: end write accounting from -\u003eki_complete\n\nCommit b000145e9907 moved both the fsnotify calls and the write\naccounting out of the kiocb completion handler and into the\nio_req_rw_complete() task_work. However, only the fsnotify part actually\nneeded to move as it may sleep. Ending the write accounting is just a\npercpu_up_read() on the superblock writers sem.\n\nDeferring it is a problem, because it makes dropping SB_FREEZE_WRITE\nprotection depend on the ring owner getting to running task_work. But\nthe task may be blocked in freeze_super(), causing it to never get to\nthat:\n\n  task                             io-wq worker\n  --------------------------------------------------------------\n  io_write()\n    io_kiocb_start_write()         (takes sb_writers, hidden from\n                                    lockdep by __sb_writers_release)\n    write_iter() -\u003e -EIOCBQUEUED\n  ioctl(FS_IOC_SHUTDOWN)\n    bdev_freeze()\n      freeze_super()\n        percpu_down_write()        \u003c- waits for the reader above\n                                   io_write()\n                                     kiocb_start_write()\n                                       percpu_down_read()  \u003c- queued\n                                                              behind the\n                                                              writer\n  \u003cbio completes\u003e\n    io_complete_rw()\n      queues io_req_rw_complete()  \u003c- never runs, task is in D state\n\nEnd the write from io_complete_rw() instead, and leave only the fsnotify\ncalls in task_work.",
  "id": "CVE-2026-97619",
  "modified": "2026-09-27T03:30:16.882487708Z",
  "published": "2026-09-25T10:22:25.644Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/055d43a1233edbd80e558889258105ce63051bcd"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/796aa0547557e63338657ed1c487906f9fac4c73"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/cc580cee4dfa2ec9099c30ecbd4d804cbb996432"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97619.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-97619"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "io_uring/rw: end write accounting from -\u003eki_complete"
}