kill -9 PID sends Linux signal 9, commonly named SIGKILL. A process cannot catch, block, or ignore it, so there is no application handler that can intercept the signal and refuse to exit. If the process remains visible afterward, it may be stuck in an uninterruptible kernel wait—not trapping SIGKILL.
What does kill -9 actually do?
The command asks the kernel to send a signal to a process. On x86, ARM, and many other Linux architectures, signal number 9 is SIGKILL; signal numbers can differ on some architectures. For clearer, more portable command syntax, use the signal name: kill -KILL PID or kill -s KILL PID. The Linux signal(7) reference documents signal dispositions and numbering.
Sending the signal and seeing a process disappear from a listing are separate events. The kill(2) interface describes signal sending; process listings report process state through procfs. A successful signal request does not promise that the process will vanish instantly.
Why can’t a process catch SIGKILL?
Most signals have a disposition: the process can use the default action, ignore the signal, or install a handler that runs application code. SIGKILL is an exception. Linux fixes its action as termination, leaving the process no option to install a handler, ignore it, or block it. The Linux signal(7) documentation identifies SIGKILL and SIGSTOP as signals that cannot be caught, blocked, or ignored.
Recommended Free Tools
#1 Best Overall
The kernel still handles signal generation, pending status, and delivery. For ordinary catchable signals, Linux checks for pending unblocked signals as execution transitions from kernel mode to user mode. SIGKILL has no user-space handler path to return from: its action is fixed by the kernel rather than chosen by the process.
Masking SIGKILL does not defer it
A signal mask normally lets a process temporarily block selected signals. SIGKILL cannot be blocked; Linux silently ignores attempts to add it to a signal mask. That rule is documented in sigprocmask(2).
Why might a process still appear after the command?
A process that remains listed has not necessarily caught SIGKILL. One possible explanation is that its task is in an uninterruptible wait inside the kernel. Linux reports this state as D in process status information. A task waiting on a kernel operation or resource may not complete the work needed to exit and disappear until that wait resolves or the kernel path can make progress. The Linux kernel documentation for /proc defines the D state as sleeping in an uninterruptible wait.
This is not a guarantee that every task in D behaves alike, nor does the state alone identify the cause or predict how long the wait will last. The delay concerns progress through a kernel wait, not a successful user-space attempt to trap the signal.
Rank #3
How to investigate a process that stays visible
-
Check the process state with
psor inspect/proc/PID/status, substituting the process ID forPID. Linux documents thatpsobtains process information from procfs; the proc documentation explains the state fields and the meaning ofD. -
If the task is reported in
D, investigate the kernel operation, I/O, or resource on which it is waiting. The state is a clue, not a diagnosis; the underlying cause depends on the host and workload. -
Allow for the possibility that the task will remain visible until the wait resolves or the kernel path can make progress. The proc documentation does not establish a universal time-to-exit.
How SIGTERM differs from SIGKILL
| Signal | Handler or ignore available? | Application cleanup opportunity | Does the request guarantee immediate disappearance? |
|---|---|---|---|
SIGTERM |
Yes. It is a catchable termination request. | Potentially. An application can arrange a handler to perform orderly cleanup. | No. Software can ignore or mishandle it, so it may not end the process. |
SIGKILL |
No. It cannot be caught, ignored, or blocked. | No user-space cleanup handler can run in response. | No. A kernel wait can delay final disappearance. |
The distinction is control: SIGTERM gives the application a chance to respond, while SIGKILL does not. Neither signal should be described as ensuring instant disappearance in every observed process state.
Free tools Windows power users keep installed
One-click scans. No signup required.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




