Kernel-level IPv6 networking bug in Linux is widespread and can cause DoS or RCE, impacting many organizations using Linux.
CVE-2026-74597
Linux IPv6 tunneling flaw allows kernel memory corruption via crafted ICMPv6 packets
Is CVE-2026-74597 being exploited?
Not confirmed. CVE-2026-74597 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.51% probability of exploitation in the next 30 days.
How severe is CVE-2026-74597?
CVE-2026-74597 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-74597?
Yes. A fix has been recorded for CVE-2026-74597. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-74597 affect?
CVE-2026-74597 affects Linux kernel (ip6_tunnel / IPv6 ICMPv6 handling), IPv6-enabled Linux hosts using tunneling. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-74597?
Apply vendor kernel updates immediately; block/limit ICMPv6 from untrusted networks
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Crafted IPv6 ICMP error packets cause OOB access in ip6_tunnel, corrupting kernel memory — may cause DoS or enable kernel RCE/privilege escalation.
Immediate action required
- affected>= e490d1d85cf5e191791979e5f260d32eb4f703a8 and < 44fe898df302e91c5ee5acbc71ffa74e78e6c183
- affected>= e490d1d85cf5e191791979e5f260d32eb4f703a8 and < 0dadb0620ab65949a8bc2439dd28ea3c942fe87d
- affected>= e490d1d85cf5e191791979e5f260d32eb4f703a8 and < b6816536a2990c0db44a26130a03e40b441e829b
- affected>= e490d1d85cf5e191791979e5f260d32eb4f703a8 and < 64e41736a26f37ab6215bc2e6df125df05aceb08
- affected>= e490d1d85cf5e191791979e5f260d32eb4f703a8 and < 484134e1eb07d700a73b1e4bbf3fb503e299be60
- affected>= e490d1d85cf5e191791979e5f260d32eb4f703a8 and < 4eb15c465337b18f44716c499cd6ad63eee0ad54
- affected>= e490d1d85cf5e191791979e5f260d32eb4f703a8 and < fbf40faa0414b753212494ad197542002e66ed9e
- affected>= e490d1d85cf5e191791979e5f260d32eb4f703a8 and < f803c086399da277b5d0ff36a107d0f162751800
- affected2.6.22
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.