Answer in brief
CVE-2026-72137 records a Unknown severity vulnerability in xfrm: nat_keepalive: avoid double free on send error. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae <d0a4dc7efa825bce60a8da8f7d43c864a159abde || >=f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae <5b0c4c916f202b8fd13d12afb6af62b385622f81 || >=f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae <a8a7e6a9ff8a4c1f067694ddbd44be67fdf36693 || >=f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae <226f4a490d1a938fc838d8f8c46a4eca864c0d78 | d0a4dc7efa825bce60a8da8f7d43c864a159abde, 5b0c4c916f202b8fd13d12afb6af62b385622f81, a8a7e6a9ff8a4c1f067694ddbd44be67fdf36693, 226f4a490d1a938fc838d8f8c46a4eca864c0d78 |
| Linux/Linuxgeneric | 6.11 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: xfrm: nat_keepalive: avoid double free on send error nat_keepalive_send() frees the keepalive skb whenever the IPv4 or IPv6 send helper reports an error. That cleanup is only correct before the skb is handed to the output path. Once ip_build_and_send_pkt() or ip6_xmit() takes ownership, the networking stack may already have consumed the skb before returning an error, so freeing it again is unsafe. Handle the pre-handoff failure cases inside nat_keepalive_send_ipv4() and nat_keepalive_send_ipv6(), where the caller still owns the skb, and keep nat_keepalive_send() responsible only for family dispatch and the unsupported-family cleanup path.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-72137 records a Unknown severity vulnerability in xfrm: nat_keepalive: avoid double free on send error. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae <d0a4dc7efa825bce60a8da8f7d43c864a159abde || >=f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae <5b0c4c916f202b8fd13d12afb6af62b385622f81 || >=f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae <a8a7e6a9ff8a4c1f067694ddbd44be67fdf36693 || >=f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae <226f4a490d1a938fc838d8f8c46a4eca864c0d78 | d0a4dc7efa825bce60a8da8f7d43c864a159abde, 5b0c4c916f202b8fd13d12afb6af62b385622f81, a8a7e6a9ff8a4c1f067694ddbd44be67fdf36693, 226f4a490d1a938fc838d8f8c46a4eca864c0d78 |
| Linux/Linuxgeneric | 6.11 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: xfrm: nat_keepalive: avoid double free on send error nat_keepalive_send() frees the keepalive skb whenever the IPv4 or IPv6 send helper reports an error. That cleanup is only correct before the skb is handed to the output path. Once ip_build_and_send_pkt() or ip6_xmit() takes ownership, the networking stack may already have consumed the skb before returning an error, so freeing it again is unsafe. Handle the pre-handoff failure cases inside nat_keepalive_send_ipv4() and nat_keepalive_send_ipv6(), where the caller still owns the skb, and keep nat_keepalive_send() responsible only for family dispatch and the unsupported-family cleanup path.
Quoted source text, attributed separately from HOL analysis.