PT-2026-38907 · Linux+3 · Linux Kernel+3

·

CVE-2026-43500

·

Published

2026-04-29

·

Updated

2026-08-26

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw in the RxRPC networking subsystem occurs when a socket buffer carrying a page-cache reference reaches the authentication verification path. The kernel performs in-place decryption directly on the referenced page without isolating the buffer. This happens because the DATA-packet handler in rxrpc input call event() and the RESPONSE handler in rxrpc verify response() only copy the socket buffer to a linear one when skb cloned() is true, failing to account for buffers that are not cloned but contain externally-owned paged fragments. A low-privileged local attacker can exploit this to corrupt page-cache contents of readable files, such as /etc/passwd, potentially obtaining root privileges. This issue may also lead to a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

LPE

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:47017
AZL-86366
BDU:2026-06470
CVE-2026-43500
ECHO-46CE-822A-3114
OPENSUSE-SU-2026:10793-1
OPENSUSE-SU-2026:20743-1
SUSE-SU-2026:1778-1
SUSE-SU-2026:1840-1
SUSE-SU-2026:1840-2
SUSE-SU-2026:1899-1
SUSE-SU-2026:1900-1
SUSE-SU-2026:1907-1
SUSE-SU-2026:1959-1
SUSE-SU-2026:2111-1
SUSE-SU-2026:21590-1
SUSE-SU-2026:21594-1
SUSE-SU-2026:21610-1
SUSE-SU-2026:21616-1
SUSE-SU-2026:21622-1
SUSE-SU-2026:21625-1
SUSE-SU-2026:21632-1
SUSE-SU-2026:21636-1
SUSE-SU-2026:21684-1
SUSE-SU-2026:21690-1
SUSE-SU-2026:2202-1
SUSE-SU-2026:2215-1
SUSE-SU-2026:2216-1
USN-8370-1
USN-8371-1
USN-8373-1
USN-8374-1
USN-8388-1
USN-8388-2
USN-8389-1
USN-8391-1
USN-8392-1
USN-8393-1
USN-8426-1
USN-8426-2
USN-8440-1
USN-8461-1
USN-8462-1
USN-8489-1
USN-8497-1
USN-8499-1
USN-8528-1
USN-8569-1
USN-8616-1

Affected Products

Linuxmint
Linux Kernel
Red Os
Ubuntu