Deadlock in Linux kernel - CVE-2026-97619
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper synchronization of write accounting in the io_uring read/write completion handling when asynchronous writes complete while filesystem shutdown is freezing the superblock. A local user can issue an asynchronous write and initiate filesystem shutdown to cause a denial of service.
The condition occurs when the ring owner blocks in freeze_super() before queued task work runs.