In the Linux kernel, the following vulnerability has been resolved: io_uring/rw: end write...
🔗 CVE IDs covered (1)
📋 Description
In the Linux kernel, the following vulnerability has been resolved:
io_uring/rw: end write accounting from ->ki_complete
Commit b000145e9907 moved both the fsnotify calls and the write accounting out of the kiocb completion handler and into the io_req_rw_complete() task_work. However, only the fsnotify part actually needed to move as it may sleep. Ending the write accounting is just a percpu_up_read() on the superblock writers sem.
Deferring it is a problem, because it makes dropping SB_FREEZE_WRITE protection depend on the ring owner getting to running task_work. But the task may be blocked in freeze_super(), causing it to never get to that:
task io-wq worker
io_write() io_kiocb_start_write() (takes sb_writers, hidden from lockdep by __sb_writers_release) write_iter() -> -EIOCBQUEUED ioctl(FS_IOC_SHUTDOWN) bdev_freeze() freeze_super() percpu_down_write() <- waits for the reader above io_write() kiocb_start_write() percpu_down_read() <- queued behind the writer io_complete_rw() queues io_req_rw_complete() <- never runs, task is in D state
End the write from io_complete_rw() instead, and leave only the fsnotify calls in task_work.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2026-97619
- https://git.kernel.org/stable/c/055d43a1233edbd80e558889258105ce63051bcd
- https://git.kernel.org/stable/c/796aa0547557e63338657ed1c487906f9fac4c73
- https://git.kernel.org/stable/c/cc580cee4dfa2ec9099c30ecbd4d804cbb996432
- https://git.kernel.org/stable/c/696459029f3b65c070c91b729478475582f1dcdf
- https://github.com/advisories/GHSA-rr3w-gg4f-957r