PT-2026-38680 · Linux+4 · Linux Kernel+4

·

CVE-2026-43284

·

Published

2026-05-04

·

Updated

2026-09-11

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An out-of-bounds buffer operation exists in the xfrm-ESP and RxRPC subsystems of the Linux kernel. Unsafe in-place cryptographic processing of shared socket buffer fragments allows a low-privileged local attacker to corrupt page-cache contents of readable files, including sensitive system files, and gain root privileges. The xfrm-ESP variant requires the creation of an unprivileged user or network namespace, while the RxRPC variant depends on the availability of the rxrpc module on the target system. The issue occurs because IPv4/IPv6 datagram append paths failed to set the SKBFL SHARED FRAG flag when splicing pages into UDP skbs, causing ESP input to decrypt data in place over fragments not privately owned by the skb.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

RCE

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:16195
ALSA-2026:16196
ALSA-2026:16206
ALSA-2026:19074
ALSA-2026:19225
ALSA-2026:19568
ALSA-2026:19569
ALSA-2026:A004
ALSA-2026:A005
ALSA-2026:A006
ALSA-2026:A007
AZL-86133
BDU:2026-06439
CVE-2026-43284
ECHO-C2C0-9DB5-201C
OESA-2026-2310
OESA-2026-2311
OESA-2026-2312
OESA-2026-2313
OESA-2026-2314
OPENSUSE-SU-2026:10793-1
OPENSUSE-SU-2026:20743-1
OPENSUSE-SU-2026:21388-1
RHSA-2026:16061
RHSA-2026:16062
RHSA-2026:16100
RHSA-2026:16195
RHSA-2026:16196
RHSA-2026:16201
RHSA-2026:16202
RHSA-2026:16203
RHSA-2026:16204
RHSA-2026:16206
RHSA-2026:16254
RHSA-2026:16312
RHSA-2026:16314
RHSA-2026:16328
RHSA-2026:17795
RHSA-2026:18025
RHSA-2026:19074
RHSA-2026:19225
RHSA-2026:19564
RHSA-2026:19568
RHSA-2026:19569
RHSA-2026:19572
RHSA-2026:19573
RHSA-2026:19574
RHSA-2026:19575
RHSA-2026:19577
RHSA-2026:33486
SUSE-SU-2026:1778-1
SUSE-SU-2026:1825-1
SUSE-SU-2026:1840-1
SUSE-SU-2026:1840-2
SUSE-SU-2026:1857-1
SUSE-SU-2026:1858-1
SUSE-SU-2026:1873-1
SUSE-SU-2026:1875-1
SUSE-SU-2026:1877-1
SUSE-SU-2026:1878-1
SUSE-SU-2026:1880-1
SUSE-SU-2026:1885-1
SUSE-SU-2026:1896-1
SUSE-SU-2026:1899-1
SUSE-SU-2026:1900-1
SUSE-SU-2026:1904-1
SUSE-SU-2026:1905-1
SUSE-SU-2026:1906-1
SUSE-SU-2026:1907-1
SUSE-SU-2026:1917-1
SUSE-SU-2026:1959-1
SUSE-SU-2026:1960-1
SUSE-SU-2026:1994-1
SUSE-SU-2026:1997-1
SUSE-SU-2026:21590-1
SUSE-SU-2026:21594-1
SUSE-SU-2026:21610-1
SUSE-SU-2026:21616-1
SUSE-SU-2026:21622-1
SUSE-SU-2026:21625-1
SUSE-SU-2026:21632-1
SUSE-SU-2026:21636-1
SUSE-SU-2026:21647-1
SUSE-SU-2026:21648-1
SUSE-SU-2026:21649-1
SUSE-SU-2026:21650-1
SUSE-SU-2026:21651-1
SUSE-SU-2026:21652-1
SUSE-SU-2026:21653-1
SUSE-SU-2026:21654-1
SUSE-SU-2026:21655-1
SUSE-SU-2026:21656-1
SUSE-SU-2026:21657-1
SUSE-SU-2026:21658-1
SUSE-SU-2026:21659-1
SUSE-SU-2026:21660-1
SUSE-SU-2026:21661-1
SUSE-SU-2026:21662-1
SUSE-SU-2026:21663-1
SUSE-SU-2026:21664-1
SUSE-SU-2026:21665-1
SUSE-SU-2026:21666-1
SUSE-SU-2026:21667-1
SUSE-SU-2026:21668-1
SUSE-SU-2026:21669-1
SUSE-SU-2026:21670-1
SUSE-SU-2026:21671-1
SUSE-SU-2026:21672-1
SUSE-SU-2026:21691-1
SUSE-SU-2026:21692-1
SUSE-SU-2026:21693-1
SUSE-SU-2026:21694-1
SUSE-SU-2026:21695-1
SUSE-SU-2026:21696-1
SUSE-SU-2026:21697-1
SUSE-SU-2026:21698-1
SUSE-SU-2026:21699-1
SUSE-SU-2026:21700-1
SUSE-SU-2026:21701-1
SUSE-SU-2026:21702-1
SUSE-SU-2026:21703-1
SUSE-SU-2026:21705-1
SUSE-SU-2026:21706-1
SUSE-SU-2026:21707-1
SUSE-SU-2026:21708-1
SUSE-SU-2026:21709-1
SUSE-SU-2026:21710-1
SUSE-SU-2026:21711-1
SUSE-SU-2026:21712-1
SUSE-SU-2026:21713-1
SUSE-SU-2026:21714-1
SUSE-SU-2026:21715-1
SUSE-SU-2026:21716-1
SUSE-SU-2026:21717-1
SUSE-SU-2026:21759-1
SUSE-SU-2026:21760-1
SUSE-SU-2026:21761-1
SUSE-SU-2026:21762-1
SUSE-SU-2026:21763-1
SUSE-SU-2026:21764-1
SUSE-SU-2026:21765-1
SUSE-SU-2026:21766-1
SUSE-SU-2026:21767-1
SUSE-SU-2026:21770-1
SUSE-SU-2026:21771-1
SUSE-SU-2026:21772-1
SUSE-SU-2026:21773-1
SUSE-SU-2026:21774-1
SUSE-SU-2026:21775-1
SUSE-SU-2026:21776-1
SUSE-SU-2026:21777-1
SUSE-SU-2026:21778-1
SUSE-SU-2026:21806-1
SUSE-SU-2026:21808-1
SUSE-SU-2026:21809-1
SUSE-SU-2026:21810-1
SUSE-SU-2026:21811-1
SUSE-SU-2026:21812-1
SUSE-SU-2026:21816-1
SUSE-SU-2026:21817-1
SUSE-SU-2026:21818-1
SUSE-SU-2026:22108-1
SUSE-SU-2026:22137-1
SUSE-SU-2026:22433-1
SUSE-SU-2026:22458-1
SUSE-SU-2026:22742-1
SUSE-SU-2026:22769-1
SUSE-SU-2026:22812-1
SUSE-SU-2026:22835-1
SUSE-SU-2026:2310-1
SUSE-SU-2026:2482-1
SUSE-SU-2026:2591-1
SUSE-SU-2026:2799-1
SUSE-SU-2026:2800-1
SUSE-SU-2026:2914-1
USN-8370-1
USN-8371-1
USN-8373-1
USN-8374-1
USN-8388-1
USN-8388-2
USN-8389-1
USN-8390-1
USN-8390-2
USN-8391-1
USN-8392-1
USN-8393-1
USN-8426-1
USN-8426-2
USN-8440-1
USN-8461-1
USN-8462-1
USN-8489-1
USN-8497-1
USN-8499-1
USN-8528-1
USN-8530-1
USN-8530-2
USN-8569-1
USN-8616-1

Affected Products

Linuxmint
Linux Kernel
Red Os
Rocky Linux
Ubuntu