Linux kernel vulnerability enabling local privilege escalation via vxlan; affects widely deployed Linux hosts, containers and multi-tenant/cloud systems — warrants broad IT notice.
CVE-2026-74615
Local Linux vxlan timer use-after-free enabling privilege escalation.
Is CVE-2026-74615 being exploited?
Not confirmed. CVE-2026-74615 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.13% probability of exploitation in the next 30 days.
How severe is CVE-2026-74615?
CVE-2026-74615 is rated High with a CVSS score of 8.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-74615?
Yes. A fix has been recorded for CVE-2026-74615. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-74615 affect?
CVE-2026-74615 affects Linux kernel (vxlan module), Container/namespace hosts, Cloud/multi-tenant Linux servers. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-74615?
Apply vendor/kernel security updates and reboot hosts; restrict unprivileged namespace creation.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Unprivileged user in a new user+network namespace can trigger a kernel use-after-free, enabling local privilege escalation (root) or kernel crash.
Immediate action required
- affected>= 40051c4dcad5b374156ad9cceae8d15c0ef1cb95 and < be44d79d14d7f9ae7c8ffb7272142005341b5123
- affected>= 40051c4dcad5b374156ad9cceae8d15c0ef1cb95 and < 26c179d47403d2f919ee914cc02c31d896b59fee
- affected>= 40051c4dcad5b374156ad9cceae8d15c0ef1cb95 and < 9dc561f0522c35bdd66e0646a748814a138ec4ca
- affected>= 40051c4dcad5b374156ad9cceae8d15c0ef1cb95 and < 619dd29045e439d0b0f8c6d4fec1af447a050680
- affected>= 40051c4dcad5b374156ad9cceae8d15c0ef1cb95 and < 6b095e99b9e67ea31f0c4b00260e010898253519
- affected>= 40051c4dcad5b374156ad9cceae8d15c0ef1cb95 and < 46bb297ad77680e009244f067f27d51cf5b8c7cf
- affected>= 40051c4dcad5b374156ad9cceae8d15c0ef1cb95 and < 6b4119af544996a545cf84b16f1dbce829ba0de8
- affected>= 40051c4dcad5b374156ad9cceae8d15c0ef1cb95 and < b37971686ec59fb027fa4910ba16805e68fddb97
- affected5.0
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.