CVE-2026-72107
Linux kernel dm-era OOB memory access allowing kernel memory corruption.
Is CVE-2026-72107 being exploited?
Not confirmed. CVE-2026-72107 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.63% probability of exploitation in the next 30 days.
How severe is CVE-2026-72107?
CVE-2026-72107 is rated High with a CVSS score of 8.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-72107?
Yes. A fix has been recorded for CVE-2026-72107. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-72107 affect?
CVE-2026-72107 affects Linux kernel (dm-era / device-mapper). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-72107?
Apply kernel security updates and reboot affected hosts.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Local writes to a dm-era mapped device can trigger out-of-bounds kernel memory access, causing crashes, memory corruption and potential privilege escalation or data disclosure.
Patch when possible
- affected>= eec40579d84873dfb7021eb24c50360f073237c5 and < fe94a0b14010a3c267ff9a2508afb4f27ff1c5bf
- affected>= eec40579d84873dfb7021eb24c50360f073237c5 and < e3ffa8e492e5cdee62d916ee3e9244ccce2b73c5
- affected>= eec40579d84873dfb7021eb24c50360f073237c5 and < 9946a7176bd8c25ddd6e5f1799c54e572ee6bf0f
- affected>= eec40579d84873dfb7021eb24c50360f073237c5 and < 7e1822f83c5a1ee7b4a19e98edde8770a10b4c71
- affected>= eec40579d84873dfb7021eb24c50360f073237c5 and < db5f9b4601f0012038e5a2628aedec2f47933380
- affected>= eec40579d84873dfb7021eb24c50360f073237c5 and < 1fcb5e29dd7a5b85adb9d8b539911741d878e829
- affected>= eec40579d84873dfb7021eb24c50360f073237c5 and < bafe3e720cdac38cd7ea4eb7852a8f2dbe1bbfe6
- affected>= eec40579d84873dfb7021eb24c50360f073237c5 and < a868196f03c2b19418ae3d2b69e195d668a271e5
- affected3.15
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.