Affects the Linux kernel network stack widely deployed across servers, routers and appliances; remote-triggerable UAF leads to kernel panic/DoS with broad operational impact.
CVE-2026-72322
Linux IPv6 MLD Use-After-Free allows remote kernel panic (DoS).
Is CVE-2026-72322 being exploited?
Not confirmed. CVE-2026-72322 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.72% probability of exploitation in the next 30 days.
How severe is CVE-2026-72322?
CVE-2026-72322 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-72322?
Yes. A fix has been recorded for CVE-2026-72322. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-72322 affect?
CVE-2026-72322 affects Linux kernel (IPv6 multicast/MLD), Servers and cloud hosts using Linux, Network appliances (routers, switches) running Linux, Embedded/IoT devices using Linux kernel. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-72322?
Apply vendor/upstream kernel patches and reboot; block/untrust IPv6 MLD where possible.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Remote attacker can send IPv6 MLD queries that trigger a Use-After-Free and kernel panic, causing host crash and denial of service.
Immediate action required
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < f12b63ef26a035c5a29b3ef56401e38199010d4a
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < 0401d6cf7877c9be36652385dfcbf7f891b8b590
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < f03b0a45535d49bdab7e502efaacee205b2a7865
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < 9815e834f5ff8b39e0ea9f0dbd532f4a3b8f0785
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < ebbebf6cee950d7f1c81990256c0eae9e62572ae
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < 9ce741c22df4fd9546e30306317ac7df3607e48f
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < 0458ba1cda830ba4ccfcd9e19c0891438bcdbe4e
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < 9b26518b6896a16b809b1e42986f4ebac7bccc1e
- affected2.6.12
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.