Kernel-level MPLS use-after-free can crash or enable kernel compromise across widely deployed Linux servers and network appliances; high-impact infrastructure vulnerability.
CVE-2026-89555
Use-after-free in Linux MPLS code enabling kernel crash or compromise.
Is CVE-2026-89555 being exploited?
Not confirmed. CVE-2026-89555 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.68% probability of exploitation in the next 30 days.
How severe is CVE-2026-89555?
CVE-2026-89555 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-89555?
Yes. A fix has been recorded for CVE-2026-89555. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-89555 affect?
CVE-2026-89555 affects Linux kernel (mpls_select_multipath), Systems using MPLS/Geneve/bareudp networking, Network appliances/routers running Linux. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-89555?
Apply kernel/vendor security updates or backport patch; block MPLS/Geneve from untrusted networks.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Crafted MPLS/Geneve packets can trigger a kernel use-after-free causing DoS or possible privilege escalation/arbitrary kernel code execution.
Immediate action required
- affected>= 9f427a0e474a67b454420c131709600d44850486 and < fed638a248116b8a249bd4202d28e5934bdc65ad
- affected>= 9f427a0e474a67b454420c131709600d44850486 and < d82b90a38c2ca8a0694428eab0e9551c23f2447d
- affected>= 9f427a0e474a67b454420c131709600d44850486 and < 49d38c1b4390412f8950d33dfaee0ccbd17beb81
- affected>= 9f427a0e474a67b454420c131709600d44850486 and < 29e63b8d9fc150cc191b1c6eb7e16e1247e1b650
- affectedad864d9fce0ec56cc8f6afe5c6a0e6d7f484b9eb
- affected>= 4.9.8 and < 4.10
- affected4.10
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.