Linux kernel bug causing kernel memory corruption/panic; affects core OS used across industries and can disrupt servers, routers, and virtualized hosts.
CVE-2026-74267
Linux kernel sch_codel bug can corrupt kernel memory and crash networked hosts.
Is CVE-2026-74267 being exploited?
Not confirmed. CVE-2026-74267 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.71% probability of exploitation in the next 30 days.
How severe is CVE-2026-74267?
CVE-2026-74267 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-74267?
Yes. A fix has been recorded for CVE-2026-74267. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-74267 affect?
CVE-2026-74267 affects Linux kernel (net/sched sch_codel), qfq + codel configurations, Routers/gateways using Linux qdiscs, Virtual hosts and containers on affected kernels. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-74267?
Install kernel update that fixes sch_codel qlen handling and reboot network-facing hosts.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Kernel memory corruption (wild memory access) leading to OOPS/panic, remote-triggerable DoS and potential for exploitation via crafted network traffic.
Immediate action required
- affected>= cc71a757da78dd4aa1b4a9b19cb011833730ccf2 and < bb9cfd874ee884117b33e92a002b9a45b48202f4
- affected>= eda741fe155ddf5ecd2dd3bfbd4fc3c0c7dbb450 and < 7a05af7f58566682b73578b72ca8e53a268c43bd
- affected>= 829c49b6b2ff45b043739168fd1245e4e1a91a30 and < eba49fd85995a3851c597fa2d214f8d21736e1d8
- affected>= 2f9761a94bae33d26e6a81b31b36e7d776d93dc1 and < e8c6dbadf139cb14ea6ed14add6ed6e88504dedd
- affected>= 4d55144b12e742404bb3f8fee6038bafbf45619d and < e4615aa6bb7802944ae790cb4b3ef8c1b7491af3
- affected>= 342debc12183b51773b3345ba267e9263bdfaaef and < 755108bb7a5083e911294c416cfea605dc75632f
- affected>= 342debc12183b51773b3345ba267e9263bdfaaef and < 91e0a793a72374c20ab31a40ccec21373e82e973
- affected>= 342debc12183b51773b3345ba267e9263bdfaaef and < 52f1da34c9f4d5bdc1e8b44242da5c7ba8db85f3
- affected7a742a9506849d1c1aa71e36c89855ceddc7d58e
- affectede73c838c80dccb9e4f19becc11d9f3cb4a27d483
- affecteda57fe60ef4cf96bfbb6b58397ec28bdb5a5c6b31
- affected>= 5.10.241 and < 5.10.261
- affected>= 5.15.190 and < 5.15.212
- affected>= 6.1.135 and < 6.1.178
- affected>= 6.6.88 and < 6.6.145
- affected>= 6.12.24 and < 6.12.97
- affected>= 5.4.297 and < 5.5
- affected>= 6.13.12 and < 6.14
- affected>= 6.14.3 and < 6.15
- affected6.15
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.