CVE-2026-72170
CVE CVE-2026-72170EUVD EUVD-2026-58928Published 2026-08-15T05:53:36.000ZLast changed 2026-08-17T05:41:08.000ZCVSS 7.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: 9p: skip nlink update in cacheless mode to fix WARN_ON v9fs_dec_count() unconditionally calls drop_nlink() on regular files, even when the inode's nlink is already zero. In cacheless mode the client refetches inode metadata from the server (the source of truth) on every operation, so by the time v9fs_remove() returns, the locally cached nlink may already reflect the post-unlink value: 1. Client initiates unlink, server processes it and sets nlink to 0 2. Client refetches inode metadata (nlink=0) before unlink returns 3. Client's v9fs_remove() completes successfully 4. Client calls v9fs_dec_count() which calls drop_nlink() on nlink=0 This race is easily triggered under heavy unlink workloads, such as stress-ng's unlink stressor, producing the following warning: WARNING: fs/inode.c:417 at drop_nlink+0x4c/0xc8 Call trace: drop_nlink+0x4c/0xc8 v9fs_remove+0x1e0/0x250 [9p] v9fs_vfs_unlink+0x20/0x38 [9p] vfs_unlink+0x13c/0x258 ... In cacheless mode the server is authoritative and the inode is on its way out, so locally adjusting nlink buys nothing. Skip v9fs_dec_count() entirely when neither CACHE_META nor CACHE_LOOSE is set, which both avoids the warning and removes a class of nlink races (two concurrent unlinkers observing nlink > 0 and both calling drop_nlink()) that an nlink == 0 guard alone would only narrow rather than close.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux ac89b2ef9b55924bcf922251f043ba73a32d05bb <de79c3f3643841b8659a71958df7cf2a66bfd409; patch: 6.18.40; 4.17; ac89b2ef9b55924bcf922251f043ba73a32d05bb <574aa0b4799470ac814479f1138d19efe6262255; patch: 7.1.5; patch: 6.12.97; ac89b2ef9b55924bcf922251f043ba73a32d05bb <8d610017c992de705b304d3d727a6e3a86af6149; ac89b2ef9b55924bcf922251f043ba73a32d05bb <a5a682b016ef5b5384e28f6d652d47a8f8e73d37; patch: 6.6.145; patch: 7.2; ac89b2ef9b55924bcf922251f043ba73a32d05bb <8faccac11e1369adddf5d80f4a45af93f13b2e1a; patch: 0
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.