Not assessed. CISA has not published an exploitation assessment for this record, and it is not in the KEV catalog. That is an absence of assessment, not a finding of no risk.
SSVC decision
Not assessed by CISA
EPSS probability
0.21% probability of exploitation activity in the next 30 days.
EPSS percentile
Ranks above 11.4% of scored records. A rank, not a probability.
NVD base score
5.5 (CVSS v3.x), scored by the NVD independently of the CNA.
NVD CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NVD analysis status
Analyzed. NVD last modified this record on 2026-06-26.
Red Hat severity
Low. Red Hat's rating for its own products, not a CVSS rating.
Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.
04 Metadata
SCHEMA: 5.2
Published
2026-03-09 15:51Z5 MO AGO
Last updated
2026-05-23 15:35Z3 MO AGO
Reserved
2026-03-09
Assigning CNA
Linux
Record state
PUBLISHED
Severity
Not rated by the issuing CNA
CNA CVSS vector
Not published by the issuing CNA
Weaknesses
CWE-401Missing Release of Memory after Effective LifetimeVariant
LinuxLinuxc03185f4a23e7f89d84c9981091770e876e64480 to < 9a3a2ae5efbbcaed37551218abed94e23c537157, c3a5e3e872f3688ae0dc57bb78ca633921d96a91 to < d151b94967c8247005435b63fc60f8f4baa320da, c3a5e3e872f3688ae0dc57bb78ca633921d96a91 to < a71874379ec8c6e788a61d71b3ad014a8d9a5c08, 8d5863cb33aa424fc27115ee945ad6b96ae2facb, 6.6.51 to < 6.6.133, 6.10.10 to < 6.11, 6.11—