Linux kernel bug in vxlan affects widely deployed OS kernels and network hosts; can be remotely triggered and impacts many environments.
CVE-2026-74473
VXLAN kernel bug allows OOB read from crafted packets, risking memory leak or crash.
Is CVE-2026-74473 being exploited?
Not confirmed. CVE-2026-74473 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.53% probability of exploitation in the next 30 days.
How severe is CVE-2026-74473?
CVE-2026-74473 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-74473?
Yes. A fix has been recorded for CVE-2026-74473. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-74473 affect?
CVE-2026-74473 affects Linux kernel (vxlan module), Linux distributions with affected kernels, Hypervisors/cloud hosts using VXLAN. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-74473?
Apply vendor kernel updates or backports; block VXLAN from untrusted networks.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Remote attacker can send crafted VXLAN packets to cause out-of-bounds kernel reads, leaking memory or crashing the host (possible exploit chain).
Immediate action required
- affected>= e4f67addf158f98f8197e08974966b18480dc751 and < c419af4924c1593500a40519730ed98575d04a3e
- affected>= e4f67addf158f98f8197e08974966b18480dc751 and < 6bd0a3a1b5744166946f0c551a6665c3b46b05e4
- affected>= e4f67addf158f98f8197e08974966b18480dc751 and < 214ba43faf106cb06cd3dd30999c5c809c868b53
- affected>= e4f67addf158f98f8197e08974966b18480dc751 and < 42887be7c4cf283cce02cd0fb6411221167c8b6c
- affected>= e4f67addf158f98f8197e08974966b18480dc751 and < aa0d31376d574ac858a40078431a77127bf04ee4
- affected>= e4f67addf158f98f8197e08974966b18480dc751 and < ee799977d7941dbfb11049e17edd9eaf4f8820f7
- affected>= e4f67addf158f98f8197e08974966b18480dc751 and < 4f3f96e771a20263635bb5e1307c112d613b4bbd
- affected>= e4f67addf158f98f8197e08974966b18480dc751 and < 26bb2dd0a8839617e2c79ffbbe1923f8e4bab9fb
- affected3.8
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.