CVE-2026-9054: 9front

Critical severity, CVSS 9.2. EPSS: 0.5% chance of exploitation in the next 30 days.

An attacker sending tcp, il, rudp, rudp, or gre packets with a length less than the header size would trigger a kernel panic.

Affected products

Published 2026-05-22. Last modified 2026-07-23.