Linux kernel vulnerability affects widespread servers, routers, VPN gateways and could disrupt infrastructure if exploited.
CVE-2026-72137
Linux kernel xfrm double-free bug may crash kernels or corrupt memory.
Is CVE-2026-72137 being exploited?
Not confirmed. CVE-2026-72137 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.66% probability of exploitation in the next 30 days.
How severe is CVE-2026-72137?
CVE-2026-72137 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-72137?
Yes. A fix has been recorded for CVE-2026-72137. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-72137 affect?
CVE-2026-72137 affects Linux kernel (xfrm/IPsec NAT keepalive), VPN gateways, Routers/firewalls using Linux, Cloud and on-prem Linux servers, and 1 further product or version. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-72137?
Apply vendor kernel updates and reboot; block IPsec NAT‑T (UDP 4500) as temporary mitigation.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Network-triggerable via IPsec/NAT-T: can crash kernel (DoS) and cause memory corruption, potentially leading to RCE.
Immediate action required
- affected>= f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae and < d0a4dc7efa825bce60a8da8f7d43c864a159abde
- affected>= f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae and < 5b0c4c916f202b8fd13d12afb6af62b385622f81
- affected>= f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae and < a8a7e6a9ff8a4c1f067694ddbd44be67fdf36693
- affected>= f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae and < 226f4a490d1a938fc838d8f8c46a4eca864c0d78
- affected6.11
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.