Linux kernel network/XDP bug affects broad deployments (hosts, containers, cloud) and can crash kernels, posing wide operational impact.
CVE-2026-74476
Linux kernel veth/XDP frag_list handling flaw can crash hosts via AF_XDP packets.
Is CVE-2026-74476 being exploited?
Not confirmed. CVE-2026-74476 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.49% probability of exploitation in the next 30 days.
How severe is CVE-2026-74476?
CVE-2026-74476 is rated Critical with a CVSS score of 9.1. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-74476?
Yes. A fix has been recorded for CVE-2026-74476. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-74476 affect?
CVE-2026-74476 affects Linux kernel (veth/XDP/AF_XDP), Hosts running AF_XDP, Containers using veth networking. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-74476?
Apply vendor kernel patches immediately, reboot affected hosts, and restrict/untrusted AF_XDP/XDP traffic.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Remote-triggerable kernel crash (Denial of Service) via crafted packets abusing veth/XDP frag_list handling and AF_XDP copy mode.
Immediate action required
- affected>= 718a18a0c8a67f97781e40bdef7cdd055c430996 and < 0be3632597b8349d43a7dc4244b492dc62a05998
- affected>= 718a18a0c8a67f97781e40bdef7cdd055c430996 and < 04958dba44dc795dc79ce2fcbc117821bbbd6542
- affected>= 718a18a0c8a67f97781e40bdef7cdd055c430996 and < 5c1c15c540fc45820ce3033c319151ec891bc10a
- affected>= 718a18a0c8a67f97781e40bdef7cdd055c430996 and < b24ba0bbffe3e23eb2f6838881c1fabcb29fb9fb
- affected>= 718a18a0c8a67f97781e40bdef7cdd055c430996 and < f9c1fff857e93be709c8b52ed1a643f37bd82c66
- affected>= 718a18a0c8a67f97781e40bdef7cdd055c430996 and < d0d6415963040c401e7a7e4e482a698ba52448cb
- affected5.18
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.