Impacts the widely deployed Linux kernel xfrm network stack; can cause kernel memory corruption enabling DoS or RCE across servers, endpoints and network appliances. High CVSS (9.8) and broad reach.
CVE-2026-92489
Linux kernel xfrm double-free leading to kernel memory corruption (DoS/RCE).
Is CVE-2026-92489 being exploited?
Not confirmed. CVE-2026-92489 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked.
How severe is CVE-2026-92489?
CVE-2026-92489 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-92489?
Yes. A fix has been recorded for CVE-2026-92489. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-92489 affect?
CVE-2026-92489 affects Linux kernel (xfrm subsystem), IPsec-enabled hosts/routers/VPN gateways, Linux distributions using affected kernels. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-92489?
Apply vendor/kernel updates immediately and reboot affected hosts.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Crafted network packets can trigger an skb double-free in xfrm, causing kernel memory corruption allowing denial-of-service or potential remote code execution.
Immediate action required
- affected>= bfb9b9404a53a72524ce695551755117e9d3deb0 and < 621871b696b108026bf4b44ed4085ffa2102f417
- affected>= a0395e96831adee8ffa016bf958e4dce9ece656e and < bc9297796bfdcc8d9609236e54519a4f38737aac
- affected>= 5eddd76ec2fd1988f0a3450fde9730b10dd22992 and < 02deb637e965950148752a304dd1471212dd6470
- affected>= 5eddd76ec2fd1988f0a3450fde9730b10dd22992 and < 56a347950e661c1a7f8f31c43a2ea53c2323b6f4
- affected>= 5eddd76ec2fd1988f0a3450fde9730b10dd22992 and < 2aed51fc58d9ce450e2c116efb956160fd06fa02
- affectedd1d673a5bede3767252cff19c0ab1e5387c6f43f
- affected>= 6.6.85 and < 6.6.157
- affected>= 6.12.21 and < 6.12.110
- affected>= 6.13.9 and < 6.14
- affected6.14
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.