SB20260816352 - Race condition in Linux kernel 9p
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Race condition (CVE-ID: CVE-2026-72170)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in v9fs_dec_count in the 9p filesystem inode handling code when processing unlink operations in cacheless mode. A local user can trigger heavy unlink workloads to cause a kernel warning and system instability.
Only systems using the 9p filesystem in cacheless mode are affected.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/574aa0b4799470ac814479f1138d19efe6262255
- https://git.kernel.org/stable/c/8d610017c992de705b304d3d727a6e3a86af6149
- https://git.kernel.org/stable/c/8faccac11e1369adddf5d80f4a45af93f13b2e1a
- https://git.kernel.org/stable/c/a5a682b016ef5b5384e28f6d652d47a8f8e73d37
- https://git.kernel.org/stable/c/de79c3f3643841b8659a71958df7cf2a66bfd409