---
id: CVE-2026-97619
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  io_uring/rw: end write accounting from ->ki_complete

  Commit b000145e9907 moved both the fsnotify calls and the write
  accounting out of the kiocb completion handler and…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  io_uring/rw: end write accounting from ->ki_complete

  Commit b000145e9907 moved both the fsnotify calls and the write
  accounting out of the kiocb completion handler and…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= b000145e9907809406d8164c3b2b8861d95aecd1 <
    cc580cee4dfa2ec9099c30ecbd4d804cbb996432
  - >-
    Linux >= b000145e9907809406d8164c3b2b8861d95aecd1 <
    055d43a1233edbd80e558889258105ce63051bcd
  - >-
    Linux >= b000145e9907809406d8164c3b2b8861d95aecd1 <
    796aa0547557e63338657ed1c487906f9fac4c73
  - Linux ea2e6286e3e89a115ae554e20ba9aec2b2e1ddff
  - Linux 89a410dbd0f159ddd308f19d6eb682fc753e4771
  - Linux 2a853c206e553dd9c0a55c22858fd6a446d93e15
  - Linux >= 5.10.165 < 5.11
  - Linux >= 5.15.90 < 5.16
  - Linux >= 6.0.3 < 6.1
  - Linux 6.1
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T11:17:16.117'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-97619'
references:
  - url: 'https://git.kernel.org/stable/c/055d43a1233edbd80e558889258105ce63051bcd'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/796aa0547557e63338657ed1c487906f9fac4c73'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/cc580cee4dfa2ec9099c30ecbd4d804cbb996432'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-25T11:06:38.897Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

io_uring/rw: end write accounting from ->ki_complete

Commit b000145e9907 moved both the fsnotify calls and the write
accounting out of the kiocb completion handler and into the
io_req_rw_complete() task_work. However, only the fsnotify part actually
needed to move as it may sleep. Ending the write accounting is just a
percpu_up_read() on the superblock writers sem.

Deferring it is a problem, because it makes dropping SB_FREEZE_WRITE
protection depend on the ring owner getting to running task_work. But
the task may be blocked in freeze_super(), causing it to never get to
that:

  task                             io-wq worker
  --------------------------------------------------------------
  io_write()
    io_kiocb_start_write()         (takes sb_writers, hidden from
                                    lockdep by __sb_writers_release)
    write_iter() -> -EIOCBQUEUED
  ioctl(FS_IOC_SHUTDOWN)
    bdev_freeze()
      freeze_super()
        percpu_down_write()        <- waits for the reader above
                                   io_write()
                                     kiocb_start_write()
                                       percpu_down_read()  <- queued
                                                              behind the
                                                              writer
  <bio completes>
    io_complete_rw()
      queues io_req_rw_complete()  <- never runs, task is in D state

End the write from io_complete_rw() instead, and leave only the fsnotify
calls in task_work.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
