Critical Linux kernel vulnerability (TIPC) affects widely deployed OS kernels; can crash or escalate privileges and should be actioned by all IT teams.
CVE-2026-72299
Local kernel use-after-free in Linux TIPC allowing crash or privilege escalation.
Is CVE-2026-72299 being exploited?
Not confirmed. CVE-2026-72299 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.74% probability of exploitation in the next 30 days.
How severe is CVE-2026-72299?
CVE-2026-72299 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-72299?
Yes. A fix has been recorded for CVE-2026-72299. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-72299 affect?
CVE-2026-72299 affects Linux kernel (TIPC subsystem). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-72299?
Apply vendor/kernel security update for TIPC immediately
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Local attacker can trigger a kernel use-after-free via TIPC socket ops, causing kernel panic (DoS) and potential local privilege escalation/arbitrary code execution.
Immediate action required
- affected>= 01e661ebfbad40e6280fb8ec25f2861d39ba4387 and < ae5d0d9ce767b20a5580bb6dc5e06f3e1b8a0fb0
- affected>= 01e661ebfbad40e6280fb8ec25f2861d39ba4387 and < 273ff83c49b82e4267373adbe629e6ee8aeaa16c
- affected>= 01e661ebfbad40e6280fb8ec25f2861d39ba4387 and < 258fb15b30db4f3941ab335d5e02f744baf1da54
- affected>= 01e661ebfbad40e6280fb8ec25f2861d39ba4387 and < 12876864f9de5fa6f611a30c6c17e405a773bf0a
- affected>= 01e661ebfbad40e6280fb8ec25f2861d39ba4387 and < b9e100815f4b55e9ccaf6af9a3aba173eb13d381
- affected>= 01e661ebfbad40e6280fb8ec25f2861d39ba4387 and < 61a55fa24a5d737436018764a647fe5b6cb36371
- affected>= 01e661ebfbad40e6280fb8ec25f2861d39ba4387 and < 6acbbe54215d5f4251593000cff2bf51d6748713
- affected>= 01e661ebfbad40e6280fb8ec25f2861d39ba4387 and < acd7df8d955480a6f6e5bb809da67b1500cc3cf4
- affected5.0
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.