PT-2026-38907 · Linux+3 · Linux Kernel+3

Hyunwoo Kim

+1

·

Published

2026-04-29

·

Updated

2026-06-26

·

CVE-2026-43500

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the RxRPC module due to incorrect handling of fragmented packets and data copying mechanisms in socket buffers. The DATA-packet handler in rxrpc input call event() and the RESPONSE handler in rxrpc verify response() only copy the socket buffer (skb) to a linear one when skb cloned() is true. If an skb is not cloned but contains externally-owned paged fragments—such as those set by splice() into a UDP socket via ip append data or a chained skb has frag list()—it proceeds to the in-place decryption path. This path binds the fragment pages directly into the AEAD/skcipher SGL (Scatter-Gather List) via skb to sgvec(). This flaw can be exploited to cause a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06470
CVE-2026-43500
ECHO-46CE-822A-3114
OPENSUSE-SU-2026:10793-1
USN-8370-1
USN-8371-1
USN-8373-1
USN-8374-1
USN-8388-1
USN-8388-2
USN-8389-1
USN-8391-1
USN-8392-1
USN-8393-1
USN-8426-1
USN-8426-2
USN-8440-1
USN-8461-1
USN-8462-1

Affected Products

Linuxmint
Linux Kernel
Red Os
Ubuntu