CVE-2026-97619

In the Linux kernel, the following vulnerability has been resolved: io_uring/rw: end write accounting from ->ki_complete Commit b000145e9907 moved both the fsnotify calls and the write accounting out of the kiocb completion handler and into the io_req_rw_complete() task_work. However, only the fsnotify part actually needed to move as it may sleep. Ending the write accounting is just a percpu_up_read() on the superblock writers sem. Deferring it is a problem, because it makes dropping SB_FREEZE_WRITE protection depend on the ring owner getting to running task_work. But the task may be blocked in freeze_super(), causing it to never get to that: task io-wq worker -------------------------------------------------------------- io_write() io_kiocb_start_write() (takes sb_writers, hidden from lockdep by __sb_writers_release) write_iter() -> -EIOCBQUEUED ioctl(FS_IOC_SHUTDOWN) bdev_freeze() freeze_super() percpu_down_write() <- waits for the reader above io_write() kiocb_start_write() percpu_down_read() <- queued behind the writer <bio completes> io_complete_rw() queues io_req_rw_complete() <- never runs, task is in D state End the write from io_complete_rw() instead, and leave only the fsnotify calls in task_work.

Package Linux Kernel
Published 2026-09-25
Last modified 2026-10-03
Patch available
Yes

Affected versions

Linux kernel versions 5.10.165, 5.15.90, 6.0.3, 6.1 and later are affected. Fixed in 6.12.112, 6.18.53, 7.2.7, 7.3-rc3 and their respective stable series.

Affected from
≥ 5.10.165 ≥ 5.15.90 ≥ 6.0.3 ≥ 6.1
Fixed in
✓ 6.12.112 6.12.x ✓ 6.18.53 6.18.x ✓ 7.2.7 7.2.x ✓ 7.3-rc3

Frequently asked questions

  • What is CVE-2026-97619?

    CVE-2026-97619 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 5.10.165 onward and has been patched in 6.12.112, 6.18.53, 7.2.7 and others. CVE-2026-97619 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-97619?

    Yes. CVE-2026-97619 has been patched. Fixed versions include 6.12.112, 6.18.53, 7.2.7 and others. If you are running Linux kernel 5.10.165 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-97619 actively exploited?

    No. CVE-2026-97619 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.