PT-2026-38680 · Linux+4 · Linux Kernel+4
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An out-of-bounds buffer operation exists in the xfrm-ESP and RxRPC subsystems of the Linux kernel. Unsafe in-place cryptographic processing of shared socket buffer fragments allows a low-privileged local attacker to corrupt page-cache contents of readable files, including sensitive system files, and gain root privileges. The xfrm-ESP variant requires the creation of an unprivileged user or network namespace, while the RxRPC variant depends on the availability of the
rxrpc module on the target system. The issue occurs because IPv4/IPv6 datagram append paths failed to set the SKBFL SHARED FRAG flag when splicing pages into UDP skbs, causing ESP input to decrypt data in place over fragments not privately owned by the skb.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
LPE
RCE
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Red Os
Rocky Linux
Ubuntu