Race condition in Linux kernel - CVE-2026-72170
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in v9fs_dec_count in the 9p filesystem inode handling code when processing unlink operations in cacheless mode. A local user can trigger heavy unlink workloads to cause a kernel warning and system instability.
Only systems using the 9p filesystem in cacheless mode are affected.
Affected software
How to mitigate CVE-2026-72170
External References
- https://git.kernel.org/stable/c/574aa0b4799470ac814479f1138d19efe6262255
- https://git.kernel.org/stable/c/8d610017c992de705b304d3d727a6e3a86af6149
- https://git.kernel.org/stable/c/8faccac11e1369adddf5d80f4a45af93f13b2e1a
- https://git.kernel.org/stable/c/a5a682b016ef5b5384e28f6d652d47a8f8e73d37
- https://git.kernel.org/stable/c/de79c3f3643841b8659a71958df7cf2a66bfd409