Linux kernel vulnerability allows remote-triggered kernel memory corruption; Linux is ubiquitous and kernel compromise would have broad, high-impact consequences.
CVE-2026-74588
Linux kernel SCTP use-after-free enabling remote kernel crash or code execution
Is CVE-2026-74588 being exploited?
Not confirmed. CVE-2026-74588 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.50% probability of exploitation in the next 30 days.
How severe is CVE-2026-74588?
CVE-2026-74588 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-74588?
Yes. A fix has been recorded for CVE-2026-74588. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-74588 affect?
CVE-2026-74588 affects Linux kernel (SCTP subsystem). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-74588?
Update Linux kernel to vendor-provided fixed version immediately.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
A remote SCTP peer can trigger a use-after-free in the kernel, causing system crash (DoS) or potentially arbitrary kernel code execution / privilege escalation.
Immediate action required
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < 6575fb17230814b48b471727c8410c0aadff9274
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < 6b9e2ea2057113f3393990ba646d2d97c719a80d
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < 874a7c2b5e184f06134fdfde27e9ce9271bafe58
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < 1adf929121e13e0b19200bb9fef715b918d483fe
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < e2e7c1de0e226ca1b7fea2de57a6c9bca408709b
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < 2b3b5eec8b2c30ee237e3c31a6a38de9c39d804d
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < 5ccf35ef0ed6059cdf8b1f4606a6584d5b67166b
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < 9f2cf069a9a72a2d6b97ca8b4c70e714aac99749
- affected2.6.12
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.