Executive brief
The Linux kernel's 9p distributed filesystem client has a race condition in how it manages file link counts during file deletion. When operating in cacheless mode, the kernel may attempt to decrement a link count that is already zero, triggering a kernel warning and potentially causing unexpected behavior. This affects systems using 9p for distributed file sharing.
Technical details
The vulnerability is a race condition in the v9fs_dec_count() function within the 9p filesystem driver (fs/9p/vfs_inode.c). The function unconditionally calls drop_nlink() to decrement an inode's link count during file deletion, but in cacheless mode the 9p client refetches metadata from the server before the removal operation completes. By the time v9fs_remove() returns, the locally cached link count may already reflect the post-deletion state (nlink=0), causing a subsequent drop_nlink() call to decrement from zero. The fix skips the v9fs_dec_count() call entirely when caching is disabled (neither CACHE_META nor CACHE_LOOSE is set), since the server is the authoritative source in cacheless mode. This removes both the kernel warning and a class of concurrent unlink races.
Affected products
- Linux Linux kernel multiple versions affected; patched in 2026
Timeline
- 2026-08-15: disclosed
- 2026-06-21: patched: Upstream fix applied; stable backport committed 2026-08-23