CVE-2026-72421
Linux kernel IPv4 routing bug can ignore 'unreachable' routes, causing misrouting.
Is CVE-2026-72421 being exploited?
Not confirmed. CVE-2026-72421 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.57% probability of exploitation in the next 30 days.
How severe is CVE-2026-72421?
CVE-2026-72421 is rated Critical with a CVSS score of 10.0. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-72421?
Yes. A fix has been recorded for CVE-2026-72421. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-72421 affect?
CVE-2026-72421 affects Linux kernel (IPv4 FIB, CONFIG_IP_MULTIPLE_TABLES), Linux servers, Containers / network namespaces. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-72421?
Install vendor kernel update; restrict CAP_NET_ADMIN; restart networking.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Local attacker with CAP_NET_ADMIN can cause kernel to ignore 'unreachable' routes, leading to traffic misrouting and segmentation bypass.
Patch when possible
- affected>= f4530fa574df4d833506c53697ed1daa0d390bf4 and < a29e95fbc51e8a1b932773fd0e259b2080881443
- affected>= f4530fa574df4d833506c53697ed1daa0d390bf4 and < 5ae18d87a45698e8244d0fcba64c658c35a7dd3d
- affected>= f4530fa574df4d833506c53697ed1daa0d390bf4 and < 9127589aabdee588278e8d0d0bd3709a760a92c8
- affected>= f4530fa574df4d833506c53697ed1daa0d390bf4 and < 49eaf1403201357762d745a35882fb734107d763
- affected>= f4530fa574df4d833506c53697ed1daa0d390bf4 and < fd25996f57a95d56bc568c89b4921edcf334b7d8
- affected>= f4530fa574df4d833506c53697ed1daa0d390bf4 and < 828fad4fd418bcdb9f5d66fec0d184c52a85ec31
- affected>= f4530fa574df4d833506c53697ed1daa0d390bf4 and < a668fa160247d7bbe921548cb845f607b8b9305f
- affected>= f4530fa574df4d833506c53697ed1daa0d390bf4 and < b72f0db64205d9ce462038ba995d5d31eff32dc1
- affected3.6
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.