GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux kernel io_uring: deferred write accounting deadlocks a task against filesystem freeze

UnscoredCVE-2026-97619Kernel, userspace & hypervisorcurated

Impact

io_uring held SB_FREEZE_WRITE protection until a task_work item ran, so a task that then blocked in freeze_super() could never release it: the freeze waits for the reader, and the reader can only be released by task_work that the frozen task will never reach. The task is left in uninterruptible D state and the filesystem stays half-frozen. For an operator this is a local, unprivileged hang that cannot be cleared by killing the process - the node needs a reboot, which on a GPU host means draining long-running training or serving jobs off it. It is a denial of service, not a memory-safety issue; the record carries no CVSS score or CWE.

Who can reach it

Local user or container workload that can submit io_uring writes and trigger a filesystem freeze path (for example FS_IOC_SHUTDOWN or a snapshot/freeze helper) on a filesystem it has access to. Requires local process access; the freeze side typically requires privilege over that filesystem.

What to do

Update to a stable kernel carrying the fix, which ends the write accounting in io_complete_rw() and leaves only the sleeping fsnotify work in task_work, then reboot each node. The record lists stable commits only - no fixed version strings - so map them onto your vendor kernel. Until then, avoid running filesystem freeze or snapshot tooling on filesystems that io_uring workloads are writing to.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.