Affects the Linux kernel network driver (enetc); kernel memory corruption can impact many Linux-based systems and infrastructure.
CVE-2026-72399
Linux kernel enetc driver OOB in XDP may allow kernel compromise or DoS.
Is CVE-2026-72399 being exploited?
Not confirmed. CVE-2026-72399 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.67% probability of exploitation in the next 30 days.
How severe is CVE-2026-72399?
CVE-2026-72399 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-72399?
Yes. A fix has been recorded for CVE-2026-72399. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-72399 affect?
CVE-2026-72399 affects Linux kernel (enetc driver), ENETC Ethernet controllers (NXP), Systems using XDP/eXpress Data Path. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-72399?
Apply vendor/kernel patch or update; disable XDP on affected interfaces until patched.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Out-of-bounds access in enetc xdp_redirect_arr via crafted XDP frames, enabling kernel memory corruption, DoS, or potential RCE.
Patch when possible
- affected>= 9d2b68cc108db2fdb35022ed2d88cfb305c441a6 and < 1ecb199b0e6d12ab6c26c0b7edf1a8f4472d9aed
- affected>= 9d2b68cc108db2fdb35022ed2d88cfb305c441a6 and < f55276160ffad3e235b657ee4b7304eb99b90e5c
- affected>= 9d2b68cc108db2fdb35022ed2d88cfb305c441a6 and < cfbc6e9b84dcc0aa2d65c84ea4745af327763209
- affected>= 9d2b68cc108db2fdb35022ed2d88cfb305c441a6 and < 1681cc7974a6123f5d5740b03bc11e4784bd2542
- affected>= 9d2b68cc108db2fdb35022ed2d88cfb305c441a6 and < d22829101ab675607ad6c3d420fb3ab875f46bbb
- affected>= 9d2b68cc108db2fdb35022ed2d88cfb305c441a6 and < 555c5475e787802eeae0d2b91c2f66c330db2767
- affected5.13
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.