CVE-2026-43284

Name
CVE-2026-43284
Description
In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(), so later paths that may modify packet data can first make a private copy. The IPv4/IPv6 datagram append paths did not set this flag when splicing pages into UDP skbs. That leaves an ESP-in-UDP packet made from shared pipe pages looking like an ordinary uncloned nonlinear skb. ESP input then takes the no-COW fast path for uncloned skbs without a frag_list and decrypts in place over data that is not owned privately by the skb. Mark IPv4/IPv6 datagram splice frags with SKBFL_SHARED_FRAG, matching TCP. Also make ESP input fall back to skb_cow_data() when the flag is present, so ESP does not decrypt externally backed frags in place. Private nonlinear skb frags still use the existing fast path. This intentionally does not change ESP output. In esp_output_head(), the path that appends the ESP trailer to existing skb tailroom without calling skb_cow_data() is not reachable for nonlinear skbs: skb_tailroom() returns zero when skb->data_len is nonzero, while ESP tailen is positive. Thus ESP output will either use the separate destination-frag path or fall back to skb_cow_data().
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Patch https://git.kernel.org/stable/c/50ed1e7873100f77abad20fd31c51029bc49cd03
Patch https://git.kernel.org/stable/c/52646cbd00e765a6db9c3afe9535f26218276034
Patch https://git.kernel.org/stable/c/5d55c7336f8032d434adcc5fab987ccc93a44aec
Patch https://git.kernel.org/stable/c/71a1d9d985d26716f74d21f18ee8cac821b06e97
416baaa9-dc9f-4396-8d5f-8c081fb06d67 https://git.kernel.org/stable/c/8253aab4659ca16116b522203c2a6b18dccacea7
Patch https://git.kernel.org/stable/c/a6cb440f274a22456ef3e86b457344f1678f38f9
Patch https://git.kernel.org/stable/c/ab8b995323e5237041472d07e5055f5f7dcdf15b
Patch https://git.kernel.org/stable/c/b54edf1e9a3fd3491bdcb82a21f8d21315271e0d
416baaa9-dc9f-4396-8d5f-8c081fb06d67 https://git.kernel.org/stable/c/fe785bb3a8096dffcc4048a85cd0c83337eeecad
Mailing List http://www.openwall.com/lists/oss-security/2026/05/08/7
Exploit https://github.com/V4bel/dirtyfrag
416baaa9-dc9f-4396-8d5f-8c081fb06d67 https://git.kernel.org/stable/c/f4c50a4034e62ab75f1d5cdd191dd5f9c77fdff4
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2026/05/13/6
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2026/05/14/2
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2026/05/14/4
af854a3a-2127-422b-91ae-364da2661108 https://www.vicarius.io/vsociety/posts/cve-2026-43284-detection-script-dirty-frag-linux-kernel-local-privilege-escalation
af854a3a-2127-422b-91ae-364da2661108 https://www.vicarius.io/vsociety/posts/cve-2026-43284-mitigation-script-dirty-frag-linux-kernel-local-privilege-escalation
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:16061
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:16062
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:16100
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:16155
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:16157
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:16160
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:16161
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:16171
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:16176
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:16180
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:16195
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:16196
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:16201
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:16202
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:16203
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:16204
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:16206
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:16254
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:16312
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:16314
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:16328
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:17795
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:18025
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:19074
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:19225
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:19564
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:19568
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:19569
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:19572
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:19573
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:19574
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:19575
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:19577
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:21695
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:23233
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:26542
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/security/cve/CVE-2026-43284
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://bugzilla.redhat.com/show_bug.cgi?id=2467771
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43284.json
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:33486
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:34098

Match rules

CPE URI Source package Min version Max version
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* linux_kernel >= 4.11 < 5.10.255
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* linux_kernel >= 5.12 < 5.15.205
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* linux_kernel >= 5.16 < 6.1.171
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* linux_kernel >= 6.2 < 6.6.138
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* linux_kernel >= 6.7 < 6.12.87
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* linux_kernel >= 6.13 < 6.18.28
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* linux_kernel >= 7.0 < 7.0.5

Vulnerable and fixed packages

Source package Branch Version Maintainer Status