{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  io_uring/rw: end write accounting from -\u003eki_complete  Commit b000145e9907 moved both the fsnotify calls and the write accounting out of the kiocb completion handler and into the io_req_rw_complete() task_work. However, only the fsnotify part actually needed to move as it may sleep. Ending the write accounting is just a percpu_up_read() on the superblock writers sem.  Deferring it is a problem, because it makes dropping SB_FREEZE_WRITE protection depend on the ring owner getting to running task_work. But the task may be blocked in freeze_super(), causing it to never get to that:    task                             io-wq worker   --------------------------------------------------------------   io_write()     io_kiocb_start_write()         (takes sb_writers, hidden from                                     lockdep by __sb_writers_release)     write_iter() -\u003e -EIOCBQUEUED   ioctl(FS_IOC_SHUTDOWN)     bdev_freeze()       freeze_super()         percpu_down_write()        \u003c- waits for the reader above                                    io_write()                                      kiocb_start_write()                                        percpu_down_read()  \u003c- queued                                                               behind the                                                               writer   \u003cbio completes\u003e     io_complete_rw()       queues io_req_rw_complete()  \u003c- never runs, task is in D state  End the write from io_complete_rw() instead, and leave only the fsnotify calls in task_work.",
  "id": "DEBIAN-CVE-2026-97619",
  "modified": "2026-09-26T04:47:42.751383896Z",
  "published": "2026-09-25T11:17:16.117Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-97619"
    }
  ],
  "upstream": [
    "CVE-2026-97619"
  ]
}