CVE-2026-43500: rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present

Published May 8, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

Other sources

The “Dirty Frag” vulnerability is a local privilege escalation (LPE) issue in the Linux kernel that combines flaws in the ESP/XFRM and RXRPC subsystems (each one separately could be used) to allow an unprivileged local attacker to gain root access on major Linux distributions. The CVE-2026-43500 is about RxRpc variant of vulnerability and the other similar CVE-2026-43284 is about ESP/XFRM variant. The attack abuses kernel page-cache manipulation and network protocol handling to overwrite privileged binaries and execute arbitrary code with elevated privileges. Exploitation differs by distribution: the ESP issue affects systems permitting unprivileged user namespaces, while the RXRPC issue impacts distributions with RXRPC enabled, such as Ubuntu. Together, the vulnerabilities provide broad cross-distribution root compromise capability, with mitigations involving disabling vulnerable kernel modules (esp4, esp6, and rxrpc) until upstream patches are fully merged and deployed.

Red Hat

Affected Software

10 affected componentsFixes available
Linux Linux kernel
Linux Linux kernel>5.3<6.18.29
Linux Linux kernel>=6.19<7.0.6
Linux Linux kernel=5.3
Linux Linux kernel=5.3-rc7
Linux Linux kernel=5.3-rc8
Linux Linux kernel=7.1-rc1
Linux Linux kernel=7.1-rc2
debian/linux<=5.10.223-1
5.10.259-16.1.176-16.1.177-16.12.94-16.12.96-17.1.3-17.1.5-1
debian/linux-6.1
6.1.177-1~deb11u1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/linux to a version that resolves this vulnerability.

    Fixed in 5.10.259-1Fixed in 6.1.176-1Fixed in 6.1.177-1Fixed in 6.12.94-1Fixed in 6.12.96-1Fixed in 7.1.3-1Fixed in 7.1.5-1
  2. Upgrade

    Upgrade debian/linux-6.1 to a version that resolves this vulnerability.

    Fixed in 6.1.177-1~deb11u1

Event History

May 8, 2026
News Published
via BleepingComputer·07:45 AM
Data Sourced
via Red Hat·03:45 PM
DescriptionSeverityAffected Software
May 9, 2026
News Published
via BleepingComputer·07:47 AM
May 11, 2026
CVE Published
via MITRE·06:26 AM
Data Sourced
via MITRE·06:26 AM
DescriptionSeverity
Data Sourced
via NVD·08:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
News Published
via Dark Reading·03:05 PM
News Published
via ZDNet·03:13 PM
News Published
via ZDNet·03:55 PM
May 12, 2026
News Published
via Dark Reading·04:01 PM
May 14, 2026
News Published
via BleepingComputer·07:30 AM
News Published
via BleepingComputer·07:34 AM
May 27, 2026
Exploit Published
via ExploitDB·12:00 AM
Known Exploited
03:17 PM
May 29, 2026
Exploit Published
via ExploitDB·12:00 AM
Jul 28, 2026
Data Sourced
via Ubuntu·07:05 AM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·07:06 AM
DescriptionAffected Software
Data Sourced
via Launchpad·07:07 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-43500?

The severity of CVE-2026-43500 is critical due to its potential to allow attackers to gain root privileges.

2

How do I fix CVE-2026-43500?

To fix CVE-2026-43500, you should update to the latest patched version of the Linux kernel.

3

What are the potential impacts of CVE-2026-43500?

CVE-2026-43500 could lead to unauthorized access and control over affected systems.

4

Which versions of the Linux kernel are affected by CVE-2026-43500?

CVE-2026-43500 affects multiple versions of the Linux kernel prior to the application of security patches.

5

How can I verify if my system is vulnerable to CVE-2026-43500?

You can check for CVE-2026-43500 vulnerabilities using system scanning tools or by reviewing your kernel version against known patched releases.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203