Software
Service
Insights
Case & Story
Dev Platform
Sign In
Public Notices
Linux Kernel Local Privilege Escalation Vulnerability (CVE-2026-43284)
Jul. 9, 2026 GMT+08:00
1.Overview

Recently, a local privilege escalation vulnerability (CVE-2026-43284, known as Dirty Frag) has been disclosed in the Linux kernel xfrm/esp subsystem. When MSG_SPLICE_PAGES attaches pages from a pipe to a UDP skb, the IPv4/IPv6 datagram append paths do not set the SKBFL_SHARED_FRAG flag. This causes ESP input to take the no-COW fast path and decrypt in place over externally-owned pages, corrupting the page cache and allowing local privilege escalation to root.

Linux kernel is the core component of Linux operating systems. Check your system and implement timely security hardening.

Reference:

https://nvd.nist.gov/vuln/detail/CVE-2026-43284

https://lore.kernel.org/linux-cve-announce/2026050856-CVE-2026-43284-6598@gregkh/

2.Severity

important

(Severity: low, medium, important, and critical)

3.Affected Products

Affected versions:

4.11 <= Linux kernel < 5.10.255

5.12 <= Linux kernel < 5.15.205

5.16 <= Linux kernel < 6.1.171

6.2 <= Linux kernel < 6.6.138

6.7 <= Linux kernel < 6.12.87

6.13 <= Linux kernel < 6.18.28

7.0 <= Linux kernel < 7.0.5

Affected OSs:

All Linux-based system distributions running an affected kernel version are impacted, including but not limited to Ubuntu, Red Hat Enterprise Linux, Oracle Linux, SUSE, Amazon Linux, and other embedded/custom systems.

Security versions:

Linux Kernel 5.10 >= 5.10.255 (commit a6cb440f274a)

Linux Kernel 5.15 >= 5.15.205 (commit ab8b995323e5)

Linux Kernel 6.1 >= 6.1.171 (commit 5d55c7336f80)

Linux Kernel 6.6 >= 6.6.138 (commit 50ed1e787310)

Linux Kernel 6.12 >= 6.12.87 (commit b54edf1e9a3f)

Linux Kernel 6.18 >= 6.18.28 (commit 71a1d9d985d2)

Linux Kernel 7.0 >= 7.0.5 (commit 52646cbd00e7)

Linux Kernel 7.1 (commit f4c50a4034e6, original fix)

5.Technical Support

Get more professional support at any time

Contact Us

Email: GlobalTechnicalService@iwhalecloud.com
Contact Us