Recently, a local privilege escalation vulnerability (CVE-2026-43500, known as Dirty Frag) has been disclosed in the Linux kernel RxRPC subsystem. The DATA/RESPONSE handlers only linearize the skb when skb_cloned() is true, but skip this step for skbs carrying externally-owned paged fragments (e.g. from splice()). This causes in-place decryption over shared pages, corrupting the page cache and allowing local privilege escalation to root.
Linux kernel is the core component of Linux operating systems. Check your system and implement timely security hardening.
Reference:
https://nvd.nist.gov/vuln/detail/CVE-2026-43500
https://lore.kernel.org/linux-cve-announce/2026051149-CVE-2026-43500-60d6@gregkh/
important
(Severity: low, medium, important, and critical)
5.3 < Linux kernel < 6.6.140
6.7 <= Linux kernel < 6.12.88
6.13 <= Linux kernel < 6.18.29
6.19 <= Linux kernel < 7.0.6
7.1-rc1, 7.1-rc2
All Linux-based system distributions running an affected kernel version are impacted, including but not limited to Ubuntu, Red Hat Enterprise Linux, Oracle Linux, SUSE, Amazon Linux, and other embedded/custom systems.
Linux Kernel 6.6 >= 6.6.140 (commit 7c504ffab3ef)
Linux Kernel 6.12 >= 6.12.88 (commit 3711382a7734)
Linux Kernel 6.18 >= 6.18.29 (commit 3eae0f4f9f72)
Linux Kernel 7.0 >= 7.0.6 (commit d45179f87952)
Linux Kernel 7.1 (commit aa54b1d27fe0, original fix)
This vulnerability has been fixed in later official versions. If your service version falls into the affected range, upgrade it to a latest secure version.
https://git.kernel.org/stable/c/7c504ffab3efce8f7e4f463b314ae31030bdf18b
https://git.kernel.org/stable/c/3711382a77342a9a1c3d2e7330dcfc7ea927f568
https://git.kernel.org/stable/c/3eae0f4f9f7206a4801efa5e0235c25bbd5a412c
https://git.kernel.org/stable/c/d45179f8795222ce858770dc619abe51f9d24411
https://git.kernel.org/stable/c/aa54b1d27fe0c2b78e664a34fd0fdf7cd1960d71
For details about the fixed versions of Linux vendors, see the security notices of Amazon Linux, Oracle Linux, Red Hat, SUSE and Ubuntu.
Note: Before fixing vulnerabilities, back up your files and conduct a thorough test.
Get more professional support at any time
Contact Us