Affects the Linux kernel (ubiquitous OS/kernel component). Kernel-level remote exploit could disrupt broad enterprise infrastructure and services.
CVE-2026-93207
Linux kernel SUNRPC GSS dangling pointer/use-after-free leading to kernel memory exposure or RCE.
Is CVE-2026-93207 being exploited?
Not confirmed. CVE-2026-93207 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked.
How severe is CVE-2026-93207?
CVE-2026-93207 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-93207?
Yes. A fix has been recorded for CVE-2026-93207. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-93207 affect?
CVE-2026-93207 affects Linux kernel (SUNRPC/GSS svc_rqst), Enterprise Linux distros (Debian/Ubuntu/RHEL/SUSE), Embedded/Appliance Linux using kernel RPC. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-93207?
Apply kernel patches or vendor updates immediately; restart affected RPC services.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Remote SUNRPC GSS requests can leave dangling pointers/stale lengths causing kernel memory disclosure, crashes, or potential remote code execution.
Immediate action required
- affected>= b0bc53470d1af01f62a0fe2d405cf56477804863 and < 56b29d62017c7dd1718d060dd5b3a2ce61095d0c
- affected>= b0bc53470d1af01f62a0fe2d405cf56477804863 and < 0e18641708eaa8bc3c1ff338cd844aeadbd52bac
- affected>= b0bc53470d1af01f62a0fe2d405cf56477804863 and < e0778464049b0238f2915a40007a4154f86cf351
- affected>= b0bc53470d1af01f62a0fe2d405cf56477804863 and < 0fa8a8acae57e6373962741d5b06d13f44aba6a9
- affected>= b0bc53470d1af01f62a0fe2d405cf56477804863 and < 11539e8fcce0b0af062ae5fecf7b3676c2f7aeed
- affected6.3
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.