Database/Kernel, userspace & hypervisor
Linux kernel io_uring: deferred write accounting deadlocks a task against filesystem freeze
Impact
io_uring held SB_FREEZE_WRITE protection until a task_work item ran, so a task that then blocked in freeze_super() could never release it: the freeze waits for the reader, and the reader can only be released by task_work that the frozen task will never reach. The task is left in uninterruptible D state and the filesystem stays half-frozen. For an operator this is a local, unprivileged hang that cannot be cleared by killing the process - the node needs a reboot, which on a GPU host means draining long-running training or serving jobs off it. It is a denial of service, not a memory-safety issue; the record carries no CVSS score or CWE.
Who can reach it
Local user or container workload that can submit io_uring writes and trigger a filesystem freeze path (for example FS_IOC_SHUTDOWN or a snapshot/freeze helper) on a filesystem it has access to. Requires local process access; the freeze side typically requires privilege over that filesystem.
What to do
Update to a stable kernel carrying the fix, which ends the write accounting in io_complete_rw() and leaves only the sleeping fsnotify work in task_work, then reboot each node. The record lists stable commits only - no fixed version strings - so map them onto your vendor kernel. Until then, avoid running filesystem freeze or snapshot tooling on filesystems that io_uring workloads are writing to.
References
Related entries
- Linux kernel x86/mm: pmd_modify() drops the dirty bit, losing written data on PMD-mapped THPCVE-2026-97945 · Linux kernel x86/mm pmd_modify() (hardware dirty bit dropped on PMD-mapped THP)Unscored
- Linux kernel powerpc/eeh: recursive locking hangs the EEH handler during PCI error recoveryCVE-2026-97948 · Linux kernel powerpc/eeh (recursive pci_rescan_remove_lock in eeh_rmv_device)Unscored
- Linux LIO iSCSI target: LUN_RESET on a WRITE_PENDING command deadlocks the target worker threadCVE-2026-97951 · Linux kernel SCSI target iSCSI frontend (aborted WRITE_PENDING dataout handling)Unscored
- Linux kernel vhost-vdpa: failed eventfd install leaves an ERR_PTR reachable by the config callbackCVE-2026-97993 · Linux kernel vhost-vdpa (ERR_PTR installed in v->config_ctx by VHOST_VDPA_SET_CONFIG_CALL)Unscored
- Linux kernel vhost-vdpa: queue size is not checked against the device maximum, giving an out-of-bounds descriptor readCVE-2026-97994 · Linux kernel vhost-vdpa (VHOST_SET_VRING_NUM validation)Unscored
- Linux kernel BPF verifier (bpf_loop nr_loops argument type): bpf_loop() declared nr_loops as ARG_ANYTHING, so aCVE-2026-98007 · Linux kernel BPF verifier (bpf_loop nr_loops argument type)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.