PT-2026-38680 · Linux+4 · Linux Kernel+4

Sandipan Roy

·

Published

2026-05-04

·

Updated

2026-06-09

·

CVE-2026-43284

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the xfrm-ESP and RxRPC subsystems of the Linux kernel involving unsafe in-place cryptographic processing of shared socket buffer fragments. Specifically, when MSG SPLICE PAGES attaches pages from a pipe directly to an skb, the IPv4/IPv6 datagram append paths fail to set the SKBFL SHARED FRAG flag when splicing pages into UDP skbs. This causes ESP-in-UDP packets made from shared pipe pages to be treated as ordinary uncloned nonlinear skbs, leading the ESP input to use a no-COW fast path and decrypt in place over data not privately owned by the skb. This out-of-bounds operation allows a low-privileged local attacker to corrupt page-cache contents of readable files, including sensitive system files, potentially resulting in root privilege escalation. The xfrm-ESP variant requires the creation of an unprivileged user or network namespace, while the RxRPC variant requires the rxrpc module to be available on the target system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

LPE

Use After Free

Weakness Enumeration

Related Identifiers

ALSA-2026:16195
ALSA-2026:16196
ALSA-2026:16206
ALSA-2026:19074
ALSA-2026:19225
ALSA-2026:19568
ALSA-2026:19569
ALSA-2026:A004
ALSA-2026:A005
ALSA-2026:A006
ALSA-2026:A007
BDU:2026-06439
CVE-2026-43284
ECHO-C2C0-9DB5-201C
OESA-2026-2310
OESA-2026-2311
OESA-2026-2312
OESA-2026-2313
OESA-2026-2314
OPENSUSE-SU-2026:10793-1
RHSA-2026:16061
RHSA-2026:16062
RHSA-2026:16100
RHSA-2026:16195
RHSA-2026:16196
RHSA-2026:16201
RHSA-2026:16202
RHSA-2026:16203
RHSA-2026:16204
RHSA-2026:16206
RHSA-2026:16254
RHSA-2026:16312
RHSA-2026:16314
RHSA-2026:16328
RHSA-2026:17795
RHSA-2026:18025
RHSA-2026:19564
RHSA-2026:19568
RHSA-2026:19569
RHSA-2026:19572
RHSA-2026:19573
RHSA-2026:19574
RHSA-2026:19575
RHSA-2026:19577
SUSE-SU-2026:2310-1
USN-8370-1
USN-8371-1
USN-8373-1
USN-8374-1
USN-8388-1
USN-8389-1
USN-8390-1
USN-8391-1
USN-8392-1
USN-8393-1

Affected Products

Linuxmint
Linux Kernel
Red Os
Rocky Linux
Ubuntu