CVE-2026-68138
Public exploit code is available. Proof-of-concept or working exploit code for CVE-2026-68138 is indexed in GitHub PoC. Expect opportunistic scanning and exploitation attempts — prioritize remediation even though it is not (yet) in the CISA KEV catalog.
An attacker can exploit multiple vulnerabilities in Linux Kernel to conduct an unspecified attack, including potentially arbitrary code execution, privilege escalation, information disclosure, data manipulation, or denial-of-service conditions.
CSIRTS triage
- What
- Multiple vulnerabilities in Linux Kernel allow arbitrary code execution, privilege escalation, information disclosure, data manipulation, and denial-of-service.
- Who is affected
- All Linux systems using affected kernel versions are at risk.
- Urgency
- Critical; kernel vulnerabilities have broad impact and enable multiple attack vectors.
- Action
- Update to the latest patched Linux kernel version for your distribution.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-68138
Get an email if CVE-2026-68138 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
Exploit availability
Public exploit or proof-of-concept code for CVE-2026-68138 is indexed in these free datasets. Available exploit code raises real-world risk independent of the CVSS score.
- GitHub PoCPublic proof-of-concept repositories on GitHub reference this CVE.look it up ↗
Advisory coverage (4)
- high[NEW] [high] Linux Kernel: Multiple vulnerabilitiescert-bund · 2026-08-25
- unknownDSA-6466-1 linux - security updatedebian · 2026-08-25
- highCVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/putmsrc · 2026-08-11
- highCVE-2026-68138: In the Linux kernel, the following vulnerability has been resolved: net/sched: serialize qdisc…nvd · 2026-08-10
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-68138)