CVE-2026-72136
Linux kernel xfrm: missing netns CAP_NET_ADMIN check allows cross-netns interface modification
Is CVE-2026-72136 being exploited?
Not confirmed. CVE-2026-72136 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.17% probability of exploitation in the next 30 days.
How severe is CVE-2026-72136?
CVE-2026-72136 is rated High with a CVSS score of 8.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-72136?
Yes. A fix has been recorded for CVE-2026-72136. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-72136 affect?
CVE-2026-72136 affects Linux kernel (xfrm interface), Systems using network namespaces (containers, multi-tenant hosts). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-72136?
Install vendor/kernel update or apply the backported patch immediately
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Local actor with CAP_NET_ADMIN in one netns can modify interfaces in another netns, enabling privilege escalation, network tampering, or container escape.
Patch when possible
- affected>= f203b76d78092faf248db3f851840fbecf80b40e and < 04c1aa57d08471b1953bf27c84ac9b3d78d71831
- affected>= f203b76d78092faf248db3f851840fbecf80b40e and < bdfd1c21d90e628a58a9de79e024cdfcbedfa15c
- affected>= f203b76d78092faf248db3f851840fbecf80b40e and < 80ec68bba11f7f387c0e4099c2d7b2c84943eb99
- affected>= f203b76d78092faf248db3f851840fbecf80b40e and < e9c90756f10da334fb31552e52c61f1dba69f491
- affected>= f203b76d78092faf248db3f851840fbecf80b40e and < 37b61946d278c7deb0d40ba8f2b6fc0478d61dab
- affected>= f203b76d78092faf248db3f851840fbecf80b40e and < 8ca2a19a987a7d1cb4c916ed9723a1c6993b4276
- affected>= f203b76d78092faf248db3f851840fbecf80b40e and < 3ba2b2ef7d6a63b190f15cfc2b4ba0fba59928ea
- affected>= f203b76d78092faf248db3f851840fbecf80b40e and < 095515d89b19b6cc19dfcdc846f97403ed1ebce3
- affected4.19
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.