PT-2026-40816 · Linux+4 · Linux Kernel+4

V4Bel

·

Published

2026-05-13

·

Updated

2026-06-29

·

CVE-2026-46300

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description Local privilege escalation is possible in the Linux kernel networking stack, specifically within the XFRM ESP-in-TCP receive path. The issue occurs when the kernel fails to correctly preserve the SKBFL SHARED FRAG flag during the movement of paged fragments between socket buffers in functions such as skb try coalesce(), pskb copy fclone(), skb shift(), skb gro receive(), skb gro receive list(), tcp clone payload(), and skb segment().
This failure creates a desynchronization between fragment metadata and page-cache-backed memory. Consequently, the skb has shared frag() check returns false, allowing the ESP input process to perform in-place decryption directly over shared page-cache pages. An unprivileged local user can exploit this memory write primitive to corrupt read-only file cache entries, such as the /usr/bin/su binary or /etc/passwd, leading to the execution of a root shell.
Recommendations As a temporary mitigation, disable the esp4, esp6, and rxrpc modules by running sudo modprobe -r esp4 esp6 rxrpc and blacklisting them. Restrict unnecessary local shell access. Harden containerized workloads. Increase monitoring for abnormal privilege escalation activity.

Exploit

Fix

DoS

LPE

RCE

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:19568
ALSA-2026:19569
ALSA-2026:19664
ALSA-2026:19666
ALSA-2026:A008
ALSA-2026:A009
ALSA-2026:A010
BDU:2026-06785
CVE-2026-46300
ECHO-AD83-3AA0-38C0
OPENSUSE-SU-2026:10954-1
RHSA-2026:19521
RHSA-2026:19540
RHSA-2026:19568
RHSA-2026:19569
RHSA-2026:19664
RHSA-2026:19666
RHSA-2026:19705
RHSA-2026:19711
RHSA-2026:19875
RHSA-2026:20051
RHSA-2026:20054
RHSA-2026:20129
RHSA-2026:20130
RHSA-2026:20299
RHSA-2026:20593
RHSA-2026:23468
RHSA-2026:23469
RHSA-2026:23470
RHSA-2026:23471
RHSA-2026:24814
SUSE-SU-2026:22029-1
SUSE-SU-2026:22030-1
SUSE-SU-2026:22031-1
SUSE-SU-2026:22032-1
SUSE-SU-2026:22033-1
SUSE-SU-2026:22034-1
SUSE-SU-2026:22035-1
SUSE-SU-2026:22038-1
SUSE-SU-2026:22039-1
SUSE-SU-2026:22040-1
SUSE-SU-2026:22042-1
USN-8370-1
USN-8371-1
USN-8373-1
USN-8374-1
USN-8388-1
USN-8388-2
USN-8393-1
USN-8426-1
USN-8426-2
USN-8440-1
USN-8461-1
USN-8462-1

Affected Products

Linuxmint
Linux Kernel
Red Os
Rocky Linux
Ubuntu