Affects Linux kernel networking code used across distributions; can crash kernels and disrupt services, warranting broad IT attention.
CVE-2026-72296
Linux kernel net/ife bug allows remote crafted IFE frames to crash kernel (DoS).
Is CVE-2026-72296 being exploited?
Not confirmed. CVE-2026-72296 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.71% probability of exploitation in the next 30 days.
How severe is CVE-2026-72296?
CVE-2026-72296 is rated Critical with a CVSS score of 9.1. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-72296?
Yes. A fix has been recorded for CVE-2026-72296. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-72296 affect?
CVE-2026-72296 affects Linux kernel (net/ife module), Linux distributions with affected kernels, Network devices using affected Linux kernels. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-72296?
Apply vendor/kernel updates ASAP; block or inspect IFE frames at network edge.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Remote denial of service: crafted IFE frames can trigger kernel crash/panic by accessing non-pullable inner Ethernet header.
Immediate action required
- affected>= ef6980b6becb1afd9d82a4f043749a10ae81bf14 and < 70013f9163bef7fbd9fa62f81cf91b2a7ba66163
- affected>= ef6980b6becb1afd9d82a4f043749a10ae81bf14 and < be272e159dfe1207b67332ad6e17adcf59b4ea4b
- affected>= ef6980b6becb1afd9d82a4f043749a10ae81bf14 and < 8c8818e52fddb247ff3214622401a4de6ff8482e
- affected>= ef6980b6becb1afd9d82a4f043749a10ae81bf14 and < 9433578bff9c100c466a6354574892e55293cb8f
- affected>= ef6980b6becb1afd9d82a4f043749a10ae81bf14 and < 1cb42ec10294a55380e52e674b3df2b962648242
- affected>= ef6980b6becb1afd9d82a4f043749a10ae81bf14 and < 5526d1997aea6c9bd865ca4d4894b52e799d735c
- affected>= ef6980b6becb1afd9d82a4f043749a10ae81bf14 and < b69ad768cd4a2ef4e07c18492ae85438ed17c7cb
- affected>= ef6980b6becb1afd9d82a4f043749a10ae81bf14 and < 9406f6012b7343661efb516a11c62d4db2b62f75
- affected4.6
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.