THE article reports on the critical vulnerability CVE-2026-72137, a double-free flaw in the Linux kernel with a CVSS score of 9.8. This vulnerability is found in the nat_keepalive component and can lead to memory corruption and privilege escalation. Discovered by researchers at NebuSec, a proof-of-concept exploit code has been released. Affected versions include those introduced between June 2024 and July 2026. Although no confirmed exploitation exists yet, swift updates to patched kernels are recommended to mitigate potential risks.
Linux Kernel Double Free Flaw CVE-2026-72137 Allows Root Access
CyberSIXT Evidence Panel
Article by CyberSIXT