Recently, a local privilege escalation vulnerability (CVE-2026-43284, known as Dirty Frag) has been disclosed in the Linux kernel xfrm/esp subsystem. When MSG_SPLICE_PAGES attaches pages from a pipe to a UDP skb, the IPv4/IPv6 datagram append paths do not set the SKBFL_SHARED_FRAG flag. This causes ESP input to take the no-COW fast path and decrypt in place over externally-owned pages, corrupting the page cache and allowing local privilege escalation to root.
Linux kernel is the core component of Linux operating systems. Check your system and implement timely security hardening.
Reference:
https://nvd.nist.gov/vuln/detail/CVE-2026-43284
https://lore.kernel.org/linux-cve-announce/2026050856-CVE-2026-43284-6598@gregkh/
important
(Severity: low, medium, important, and critical)
4.11 <= Linux kernel < 5.10.255
5.12 <= Linux kernel < 5.15.205
5.16 <= Linux kernel < 6.1.171
6.2 <= Linux kernel < 6.6.138
6.7 <= Linux kernel < 6.12.87
6.13 <= Linux kernel < 6.18.28
7.0 <= Linux kernel < 7.0.5
All Linux-based system distributions running an affected kernel version are impacted, including but not limited to Ubuntu, Red Hat Enterprise Linux, Oracle Linux, SUSE, Amazon Linux, and other embedded/custom systems.
Linux Kernel 5.10 >= 5.10.255 (commit a6cb440f274a)
Linux Kernel 5.15 >= 5.15.205 (commit ab8b995323e5)
Linux Kernel 6.1 >= 6.1.171 (commit 5d55c7336f80)
Linux Kernel 6.6 >= 6.6.138 (commit 50ed1e787310)
Linux Kernel 6.12 >= 6.12.87 (commit b54edf1e9a3f)
Linux Kernel 6.18 >= 6.18.28 (commit 71a1d9d985d2)
Linux Kernel 7.0 >= 7.0.5 (commit 52646cbd00e7)
Linux Kernel 7.1 (commit f4c50a4034e6, original fix)
This vulnerability has been fixed in later official versions. If your service version falls into the affected range, upgrade it to a latest secure version.
https://git.kernel.org/stable/c/a6cb440f274a22456ef3e86b457344f1678f38f9
https://git.kernel.org/stable/c/ab8b995323e5237041472d07e5055f5f7dcdf15b
https://git.kernel.org/stable/c/5d55c7336f8032d434adcc5fab987ccc93a44aec
https://git.kernel.org/stable/c/50ed1e7873100f77abad20fd31c51029bc49cd03
https://git.kernel.org/stable/c/b54edf1e9a3fd3491bdcb82a21f8d21315271e0d
https://git.kernel.org/stable/c/71a1d9d985d26716f74d21f18ee8cac821b06e97
https://git.kernel.org/stable/c/52646cbd00e765a6db9c3afe9535f26218276034
https://git.kernel.org/stable/c/f4c50a4034e62ab75f1d5cdd191dd5f9c77fdff4
For details about the fixed versions of Linux vendors, see the security notices of Amazon Linux, Oracle Linux, Red Hat, SUSE and Ubuntu.
Note: Before fixing vulnerabilities, back up your files and conduct a thorough test.
Get more professional support at any time
Contact Us