Kernel-level use-after-free in widely deployed Linux kernels (RT/preemptible) can enable local root compromise across servers and devices; organization-wide attention required.
CVE-2026-72069
Linux kernel RT spin_unlock() use-after-free enabling local kernel compromise
Is CVE-2026-72069 being exploited?
Not confirmed. CVE-2026-72069 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.73% probability of exploitation in the next 30 days.
How severe is CVE-2026-72069?
CVE-2026-72069 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-72069?
Yes. A fix has been recorded for CVE-2026-72069. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-72069 affect?
CVE-2026-72069 affects Linux kernel (preemptible/RT variants), Distributions with PREEMPT_RT/backported RT patches, Android/embedded kernels using RT patches. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-72069?
Apply vendor/upstream kernel updates or RT backport, reboot hosts, restrict local access until patched.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Local use-after-free causing kernel memory corruption; can enable local privilege escalation to root and kernel compromise.
Patch when possible
- affected>= 0f383b6dc96e976dfbf2721b0bf10bd96103b341 and < af28d801cd2db4cc7378554499bd4a5d84a5517e
- affected>= 0f383b6dc96e976dfbf2721b0bf10bd96103b341 and < 9d1fcd64ab81200e02b7a6db5eb1da8e244e8289
- affected>= 0f383b6dc96e976dfbf2721b0bf10bd96103b341 and < 3cfaac77b3c32ac3940df28866de263c3f45d24c
- affected>= 0f383b6dc96e976dfbf2721b0bf10bd96103b341 and < 1f0d56d3f1e88f20f6e46109402f8c15d59bac37
- affected>= 0f383b6dc96e976dfbf2721b0bf10bd96103b341 and < 633cadbc0b8323f5cc140a285d2432089dbb534e
- affected>= 0f383b6dc96e976dfbf2721b0bf10bd96103b341 and < 83f9fb561c1c3917e19f95523dd933c7d30291aa
- affected>= 0f383b6dc96e976dfbf2721b0bf10bd96103b341 and < 89038cc87d80c77e7aa6f42a64b2573b74af339f
- affected5.15
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.