Junglewise Threat Intelligence

CVE-2026-72170: Linux kernel 9p filesystem race condition in link count handling

CVE-2026-72170 · Severity: high · CVSS 7.8 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's 9p distributed filesystem client has a race condition in how it manages file link counts during file deletion. When operating in cacheless mode, the kernel may attempt to decrement a link count that is already zero, triggering a kernel warning and potentially causing unexpected behavior. This affects systems using 9p for distributed file sharing.

Technical details

The vulnerability is a race condition in the v9fs_dec_count() function within the 9p filesystem driver (fs/9p/vfs_inode.c). The function unconditionally calls drop_nlink() to decrement an inode's link count during file deletion, but in cacheless mode the 9p client refetches metadata from the server before the removal operation completes. By the time v9fs_remove() returns, the locally cached link count may already reflect the post-deletion state (nlink=0), causing a subsequent drop_nlink() call to decrement from zero. The fix skips the v9fs_dec_count() call entirely when caching is disabled (neither CACHE_META nor CACHE_LOOSE is set), since the server is the authoritative source in cacheless mode. This removes both the kernel warning and a class of concurrent unlink races.

Affected products

  • Linux Linux kernel multiple versions affected; patched in 2026

Timeline

  • 2026-08-15: disclosed
  • 2026-06-21: patched: Upstream fix applied; stable backport committed 2026-08-23

References

Related threats