PT-2026-40816 · Linux+4 · Linux Kernel+4

V4Bel

·

Published

2026-05-13

·

Updated

2026-06-08

·

CVE-2026-46300

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to May 13, 2026
Description A local privilege escalation issue exists in the Linux kernel networking stack, specifically within the XFRM ESP-in-TCP subsystem. The problem stems from a logical error in several functions, including skb try coalesce(), pskb copy fclone(), skb shift(), skb gro receive(), skb gro receive list(), tcp clone payload(), and skb segment(), which fail to correctly propagate the SKBFL SHARED FRAG flag when moving paged fragments between socket buffers. This flag is used to identify fragments that are externally owned or backed by the page cache.
When this marker is lost, the system may incorrectly report skb has shared frag() as false. This allows in-place writers, such as ESP input (esp4.c, esp6.c), to skip the skb cow data() function and perform decryption directly over shared page-cache pages. An unprivileged local user can exploit this to achieve arbitrary byte writes into the kernel page cache of read-only files, such as /usr/bin/su or /etc/passwd, without requiring a race condition. This enables the attacker to corrupt protected system binaries in memory and escalate privileges to root. A variant of this issue also exists where skb segment() fails to merge flags from the frag list members, allowing a similar bypass of the skip cow() check inside esp input().
Recommendations Update the Linux kernel to a version released after May 13, 2026. As a temporary mitigation, disable the esp4, esp6, and rxrpc modules by running sudo modprobe -r esp4 esp6 rxrpc and blacklisting them.

Exploit

Fix

RCE

DoS

LPE

Memory Corruption

Weakness Enumeration

Related Identifiers

ALSA-2026:19568
ALSA-2026:19569
ALSA-2026:19664
ALSA-2026:19666
ALSA-2026:A008
ALSA-2026:A009
ALSA-2026:A010
BDU:2026-06785
CVE-2026-46300
ECHO-AD83-3AA0-38C0
OPENSUSE-SU-2026:10954-1
RHSA-2026:19521
RHSA-2026:19540
RHSA-2026:19568
RHSA-2026:19569
RHSA-2026:19664
RHSA-2026:19666
RHSA-2026:19705
RHSA-2026:19711
RHSA-2026:19875
RHSA-2026:20051
RHSA-2026:20054
RHSA-2026:20129
RHSA-2026:20130
RHSA-2026:20299
RHSA-2026:20593
SUSE-SU-2026:22029-1
SUSE-SU-2026:22030-1
SUSE-SU-2026:22031-1
SUSE-SU-2026:22032-1
SUSE-SU-2026:22033-1
SUSE-SU-2026:22034-1
SUSE-SU-2026:22035-1
SUSE-SU-2026:22038-1
SUSE-SU-2026:22039-1
SUSE-SU-2026:22040-1
SUSE-SU-2026:22042-1
USN-8370-1
USN-8371-1
USN-8373-1
USN-8374-1
USN-8388-1
USN-8393-1

Affected Products

Linuxmint
Linux Kernel
Red Os
Rocky Linux
Ubuntu