Linux kernel netfilter bug affects kernel networking stack used broadly across servers, routers, cloud hosts; can cause service-impacting crashes and outages.
CVE-2026-72248
Linux kernel netfilter flowtable bug causes IPIP tunnel direct-xmit crashes (DoS).
Is CVE-2026-72248 being exploited?
Not confirmed. CVE-2026-72248 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.52% probability of exploitation in the next 30 days.
How severe is CVE-2026-72248?
CVE-2026-72248 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-72248?
Yes. A fix has been recorded for CVE-2026-72248. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-72248 affect?
CVE-2026-72248 affects Linux kernel (netfilter/flowtable), Systems using IPIP tunnels, Bridged devices/routers using direct xmit, Cloud hosts running Linux networking stacks. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-72248?
Apply latest Linux kernel/netfilter patch and reboot affected systems handling IPIP/bridges.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Remote/locally reachable attackers can trigger kernel crash/packet-forwarding outage via IPIP tunnel with direct xmit (denial of service).
Patch when possible
- affected>= d30301ba4b07ac92eb38353a111833b009003170 and < 0880c4ed122d0cddc9f29a2b28f055d1f24f0fca
- affected>= d30301ba4b07ac92eb38353a111833b009003170 and < fa7395c02d95e51bad2952325d2d6503bfbad437
- affected6.19
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.