CVE-2026-9054
CVE-2026-9054 is a critical-severity vulnerability with a CVSS 4.0 base score of 9.2. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-130.
Key facts
- Severity: Critical (CVSS 4.0 base score 9.2)
- EPSS exploit prediction: 1% (41st percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-31403
- Weakness: CWE-130
- Published:
- Last modified:
Description
An attacker sending tcp, il, rudp, rudp, or gre packets with a length less than the header size would trigger a kernel panic.
Frequently asked questions
- What is CVE-2026-9054?
- An attacker sending tcp, il, rudp, rudp, or gre packets with a length less than the header size would trigger a kernel panic.
- How severe is CVE-2026-9054?
- CVE-2026-9054 has a CVSS 4.0 base score of 9.2, rated critical severity.
- Is CVE-2026-9054 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (41st percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-9054?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- Does CVE-2026-9054 have an EU (EUVD) identifier?
- Yes. CVE-2026-9054 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-31403.
- When was CVE-2026-9054 published?
- CVE-2026-9054 was published on 2026-05-22 and last updated on 2026-07-23.
References
- https://git.9front.org/plan9front/9front/70c97c334171c715df82774d1a47638abaca2db4/commit.html
- https://git.9front.org/plan9front/9front/7838d68969549f938cc8e80c0c2b4218cb12805c/commit.html
- https://git.9front.org/plan9front/9front/f86917b75e9562f90545b7e484dbdcd748236952/commit.html
Other CWE-130 vulnerabilities
- CVE-2022-2714 — Critical (CVSS 9.8): Improper Handling of Length Parameter Inconsistency in GitHub repository francoisjacquet/rosariosis prior to 10.0.
- CVE-2026-18397 — Critical (CVSS 9.4): This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a…
- CVE-2026-5706 — High (CVSS 8.9): In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to…
- CVE-2026-58096 — High (CVSS 8.8): LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required…
- CVE-2022-1543 — High (CVSS 8.8): Improper handling of Length parameter in GitHub repository erudika/scoold prior to 1.49.4. When the text size is large…
- CVE-2026-83745 — High (CVSS 8.7): Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in…