CVE-2026-43500
Description
In the Linux kernel, the following vulnerability has been resolved:
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
The DATA-packet handler in rxrpc_input_call_event() and the RESPONSE handler in rxrpc_verify_response() copy the skb to a linear one before calling into the security ops only when skb_cloned() is true. An skb that is not cloned but still carries externally-owned paged fragments (e.g. SKBFL_SHARED_FRAG set by splice() into a UDP socket via __ip_append_data, or a chained skb_has_frag_list()) falls through to the in-place decryption path, which binds the frag pages directly into the AEAD/skcipher SGL via skb_to_sgvec().
Extend the gate to also unshare when skb_has_frag_list() or skb_has_shared_frag() is true. This catches the splice-loopback vector and other externally-shared frag sources while preserving the zero-copy fast path for skbs whose frags are kernel-private (e.g. NIC page_pool RX, GRO). The OOM/trace handling already in place is reused.
Affected products
7cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >5.3,<6.18.29
- cpe:2.3:o:linux:linux_kernel:5.3:-:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:5.3:rc7:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:5.3:rc8:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
News mentions
50- Russian hackers turn Kazuar backdoor into modular P2P botnetBleepingComputer · May 16, 2026
- Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent AccessThe Hacker News · May 15, 2026
- Rocky Linux launches opt-in security repository for urgent fixesHelp Net Security · May 15, 2026
- Fragnesia (CVE-2026-46300): Frequently asked questions about new Linux Kernel XFRM ESP-in-TCP privilege escalationTenable Blog · May 14, 2026
- Fragnesia: New Linux kernel LPE bug was spawned by Dirty Frag patch (CVE-2026-46300)Help Net Security · May 14, 2026
- Enhancing Data Center Security Without Sacrificing PerformanceSecurityWeek · May 14, 2026
- New Linux Kernel Vulnerability Fragnesia Allows Root Privilege EscalationSecurityWeek · May 14, 2026
- Dirty Frag gets a sequel as Fragnesia hands Linux attackers root-level accessThe Register Security · May 14, 2026
- New Fragnesia Linux flaw lets attackers gain root privilegesBleepingComputer · May 14, 2026
- Researcher Drops YellowKey, GreenPlasma Windows Zero-DaysSecurityWeek · May 14, 2026
- New Fragnesia Linux Kernel LPE Grants Root Access via Page Cache CorruptionThe Hacker News · May 14, 2026
- Welcome to the vulnpocalypse, as vendors use AI to find bugs and patches multiply like rabbitsThe Register Security · May 13, 2026
- Windows BitLocker zero-day gives access to protected drives, PoC releasedBleepingComputer · May 13, 2026
- Microsoft, Palo Alto Networks Find Many Vulnerabilities by Using AI on Their Own CodeSecurityWeek · May 13, 2026
- When IT Support Calls: Dissecting a ModeloRAT Campaign from Teams to Domain CompromiseRapid7 Blog · May 13, 2026
- Microsoft on pace to break annual vulnerability record as AI-driven patch wave takes holdThe Record · May 13, 2026
- Microsoft’s agentic security system found four critical Windows RCE flawsHelp Net Security · May 13, 2026
- Researchers open-source a Wi-Fi cyber range for security trainingHelp Net Security · May 13, 2026
- Patch Tuesday - May 2026Rapid7 Blog · May 13, 2026
- Fedora Hummingbird brings the container security model to a Linux host OSHelp Net Security · May 12, 2026
- Microsoft Patch Tuesday for May 2026 — Snort rules and prominent vulnerabilitiesCisco Talos Intelligence · May 12, 2026
- Microsoft May 2026 Patch Tuesday: Many fixes, but no zero-daysHelp Net Security · May 12, 2026
- Microsoft May 2026 Patch Tuesday, (Tue, May 12th)SANS Internet Storm Center · May 12, 2026
- Microsoft May 2026 Patch Tuesday fixes 120 flaws, no zero-daysBleepingComputer · May 12, 2026
- Microsoft Patches 137 VulnerabilitiesSecurityWeek · May 12, 2026
- Microsoft’s May 2026 Patch Tuesday Addresses 118 CVEs (CVE-2026-41103)Tenable Blog · May 12, 2026
- When "idle" isn't idle: how a Linux kernel optimization became a QUIC bugCloudflare Blog · May 12, 2026
- Copy.Fail Linux VulnerabilitySchneier on Security · May 12, 2026
- iOS 26.5 Brings Default End-to-End Encrypted RCS Messaging Between iPhone and AndroidThe Hacker News · May 12, 2026
- Apple Patches Everything, (Mon, May 11th)SANS Internet Storm Center · May 11, 2026
- 'Dirty Frag' Exploit Poised to Blow Up on Enterprise Linux DistrosDark Reading · May 11, 2026
- Linux developers weigh emergency “killswitch” for vulnerable kernel functionsHelp Net Security · May 11, 2026
- 11th May – Threat Intelligence ReportCheck Point Research · May 11, 2026
- ⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and MoreThe Hacker News · May 11, 2026
- Dirty Frag: Linux kernel hit by second major security flaw in two weeksThe Record · May 11, 2026
- New ‘Dirty Frag’ Linux Vulnerability Possibly Exploited in AttacksSecurityWeek · May 11, 2026
- Rustinel: Open-source endpoint detection for Windows and LinuxHelp Net Security · May 11, 2026
- Dirty Frag (CVE-2026-43284, CVE-2026-43500): Frequently asked questions about this Linux kernel privilege escalation vulnerability chainTenable Blog · May 8, 2026
- Another Universal Linux Local Privilege Escalation (LPE) Vulnerability: Dirty Frag, (Fri, May 8th)SANS Internet Storm Center · May 8, 2026
- Dirty Frag: Unpatched Linux vulnerability delivers root accessHelp Net Security · May 8, 2026
- 'Dirty Frag' Linux flaw one-ups CopyFail with no patches and public root exploitThe Register Security · May 8, 2026
- Quasar Linux RAT Steals Developer Credentials for Software Supply Chain CompromiseThe Hacker News · May 8, 2026
- New Linux 'Dirty Frag' zero-day gives root on all major distrosBleepingComputer · May 8, 2026
- Linux Kernel Dirty Frag LPE Exploit Enables Root Access Across Major DistributionsThe Hacker News · May 8, 2026
- Unplug your way to better codeCisco Talos Intelligence · May 7, 2026
- Palo Alto Zero-Day Exploited in Campaign Bearing Hallmarks of Chinese State HackingSecurityWeek · May 7, 2026
- PAN-OS RCE Exploit Under Active Use Enabling Root Access and EspionageThe Hacker News · May 7, 2026
- How Cloudflare responded to the “Copy Fail” Linux vulnerabilityCloudflare Blog · May 7, 2026
- Sysdig delivers cloud security that runs inside AI coding agentsHelp Net Security · May 6, 2026
- Sophisticated Quasar Linux RAT Targets Software DevelopersSecurityWeek · May 6, 2026