
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-72137 is a double-free vulnerability in the Linux kernel's xfrm (IPsec transform) subsystem, specifically in the nat_keepalive_send() function. The flaw allows an unauthenticated network attacker to trigger kernel memory corruption by causing a NAT keepalive send operation to encounter an error condition after the socket buffer (skb) has already been handed off to the networking stack. Affected versions span Linux kernel 6.11 through unpatched 6.12.x, 6.18.x, and 7.1.x branches. It was published on August 15, 2026, and carries a CVSS v3.1 base score of 9.8 (Critical) (Feedly, EUVD).
The root cause is a double-free condition (CWE-415) in nat_keepalive_send() within the kernel's xfrm NAT keepalive path. When ip_build_and_send_pkt() (IPv4) or ip6_xmit() (IPv6) takes ownership of the skb and subsequently returns an error, the networking stack may have already consumed and freed the skb internally; the caller's unconditional kfree_skb() on error then frees already-released memory. The fix restructures ownership semantics by moving pre-handoff error handling into nat_keepalive_send_ipv4() and nat_keepalive_send_ipv6(), ensuring the skb is only freed when the caller still owns it, while nat_keepalive_send() retains responsibility only for family dispatch and unsupported-family cleanup (Feedly, Kernel Commits).
Successful exploitation can result in kernel memory corruption leading to arbitrary code execution with kernel (ring-0) privileges, enabling full system compromise. An unauthenticated attacker reachable over the network can exploit this to gain complete control over confidentiality, integrity, and availability of the affected host. Given kernel-level access, lateral movement to other systems, credential harvesting, and persistent backdoor installation are all plausible post-exploitation outcomes (Feedly).
A public proof-of-concept (PoC) has been published in a GitHub repository (NebuSec/CyberMeowfia) targeting Ubuntu 7.0.0-28, and security news outlets have reported on the local privilege escalation risk (SecurityOnline, BugsToday). No confirmed in-the-wild exploitation or threat actor attribution has been reported as of the latest update. The EPSS score is approximately 0.0021 (0.21%), indicating low but non-zero probability of exploitation in the near term. The vulnerability is not currently listed in the CISA KEV catalog (Feedly).
nat_keepalive_send() function is invoked periodically.ip_build_and_send_pkt() or ip6_xmit() returns an error after taking ownership of the skb — for example, by causing a route lookup failure or interface teardown at the right moment.nat_keepalive_send() to call kfree_skb() on an skb already consumed by the networking stack, corrupting kernel heap memory.nat_keepalive_send, kfree_skb, or xfrm subsystem in /var/log/kern.log or dmesg; KASAN (Kernel Address Sanitizer) reports indicating double-free in xfrm/nat_keepalive code paths./tmp or /dev/shm consistent with exploit staging; new cron jobs or systemd services created post-exploitation.Apply the Linux kernel patches that resolve the double-free by restructuring skb ownership in the NAT keepalive send path. Fixed versions are: 6.12.101 (for 6.12.x branch), 6.18.40 (for 6.18.x branch), 7.1.5 (for 7.1.x branch), and 7.2-rc4 or later. The corresponding fix commits are d0a4dc7e, 5b0c4c91, a8a7e6a9, and 226f4a49 (Kernel Commits, Feedly). As a temporary workaround where patching is not immediately possible, disabling IPsec NAT traversal (NAT-T) keepalives or restricting network access to IPsec endpoints via firewall rules can reduce exposure. Prioritize patching given the critical CVSS score and availability of a public PoC.
Security news outlet SecurityOnline.info covered the vulnerability with a focus on the local privilege escalation risk, and BugsToday reported on the public PoC release (SecurityOnline, BugsToday). The vulnerability was also noted on Mastodon's infosec.exchange community by DailyCyberSecurity. Qualys has added detection for this CVE (detection ID 6663341), and Tenable published a Nessus plugin (ID 337414) for scanning (Tenable).
Fix availability across major Linux distributions and their releases.
bookworm
linux-6.12: 6.12.101-1~deb12u1
sid
linux: 7.1.5-1
trixie
linux: 6.12.101-1
bionic
linux
bionic (esm-infra)
linux
bionic (fips-updates)
linux-fips
bionic (fips)
linux-fips
devel
linux-realtime: 7.3.0-6.6.1
focal
linux
focal (esm-infra)
linux
focal (fips-updates)
linux-fips
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."