Kernel-level vulnerability in the Linux ovpn data path can affect widely deployed Linux systems and VPN infrastructure, enabling disruptive kernel corruption or RCE across enterprises.
CVE-2026-74727
Linux kernel ovpn race causes use-after-free, enabling kernel memory corruption.
Is CVE-2026-74727 being exploited?
Not confirmed. CVE-2026-74727 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.44% probability of exploitation in the next 30 days.
How severe is CVE-2026-74727?
CVE-2026-74727 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-74727?
Yes. A fix has been recorded for CVE-2026-74727. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-74727 affect?
CVE-2026-74727 affects Linux kernel (net/ovpn module), Kernels with OVPN/ovpn_nl enabled, Systems using kernel-integrated OpenVPN/VPN datapath. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-74727?
Install vendor/kernel updates immediately; restart VPN services and isolate unpatched hosts.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Race in ovpn peer rehash permits use-after-free via VPN/network operations, causing kernel memory corruption, crashes, and potential privilege escalation or RCE.
Immediate action required
- affected>= 1d36a36f6d5347360ef9681a05f6166683bafd1d and < d20c181088984b6eaa8d7fe7cb5ab3510988df59
- affected>= 1d36a36f6d5347360ef9681a05f6166683bafd1d and < 66745480298775f188b2f5ad266643e85a90f73b
- affected>= 1d36a36f6d5347360ef9681a05f6166683bafd1d and < 33ec10567fe14456063daf549fdf1a4f53448e4c
- affected6.16
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.