Critical Alert 1 Active Exploit Detected Today

CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

← Back to CVE List

CVE-2026-92489NVD

Vulnerability Summary

In the Linux kernel, the following vulnerability has been resolved:

xfrm: Fix skb double-free in xfrm_dev_direct_output()

A return value other than 1 from local_out() means that the skb has been
consumed or its ownership was transferred. xfrm_dev_direct_output()
nevertheless frees the skb on this path, causing a double-free when
netfilter drops the packet and invalidating any other owner.

Return the local_out() result directly, matching the ownership handling
in xfrm_output_resume().
Severity Level
CRITICAL(9.8)
Published Date
Sep 17, 2026
Last Modified
Sep 18, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.46%Probability
Root Weakness (CWE)
N/A
CVSS v3.1 Base Metrics — Score 9.8 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh

Affected & Patched Versions

Affected Versions
  • Linux Linux >= bfb9b9404a53a72524ce695551755117e9d3deb0 and < 621871b696b108026bf4b44ed4085ffa2102f417
  • Linux Linux >= a0395e96831adee8ffa016bf958e4dce9ece656e and < bc9297796bfdcc8d9609236e54519a4f38737aac
  • Linux Linux >= 5eddd76ec2fd1988f0a3450fde9730b10dd22992 and < 02deb637e965950148752a304dd1471212dd6470
  • Linux Linux >= 5eddd76ec2fd1988f0a3450fde9730b10dd22992 and < 56a347950e661c1a7f8f31c43a2ea53c2323b6f4
  • Linux Linux >= 5eddd76ec2fd1988f0a3450fde9730b10dd22992 and < 2aed51fc58d9ce450e2c116efb956160fd06fa02
  • Linux Linux >= d1d673a5bede3767252cff19c0ab1e5387c6f43f
  • Linux Linux >= 6.6.85 and < 6.6.157
  • Linux Linux >= 6.12.21 and < 6.12.110
  • Linux Linux >= 6.13.9 and < 6.14
  • Linux Linux >= 6.14
Patched Versions
  • Linux Linux 621871b696b108026bf4b44ed4085ffa2102f417
  • Linux Linux bc9297796bfdcc8d9609236e54519a4f38737aac
  • Linux Linux 02deb637e965950148752a304dd1471212dd6470
  • Linux Linux 56a347950e661c1a7f8f31c43a2ea53c2323b6f4
  • Linux Linux 2aed51fc58d9ce450e2c116efb956160fd06fa02
  • Linux Linux 6.6.157
  • Linux Linux 6.12.110
  • Linux Linux 6.14
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.