CVE-2026-43500: rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
In the Linux kernel, the following vulnerability has been resolved:
Other sources
The “Dirty Frag” vulnerability is a local privilege escalation (LPE) issue in the Linux kernel that combines flaws in the ESP/XFRM and RXRPC subsystems (each one separately could be used) to allow an unprivileged local attacker to gain root access on major Linux distributions. The CVE-2026-43500 is about RxRpc variant of vulnerability and the other similar CVE-2026-43284 is about ESP/XFRM variant. The attack abuses kernel page-cache manipulation and network protocol handling to overwrite privileged binaries and execute arbitrary code with elevated privileges. Exploitation differs by distribution: the ESP issue affects systems permitting unprivileged user namespaces, while the RXRPC issue impacts distributions with RXRPC enabled, such as Ubuntu. Together, the vulnerabilities provide broad cross-distribution root compromise capability, with mitigations involving disabling vulnerable kernel modules (esp4, esp6, and rxrpc) until upstream patches are fully merged and deployed.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.259-1Fixed in 6.1.176-1Fixed in 6.1.177-1Fixed in 6.12.94-1Fixed in 6.12.96-1Fixed in 7.1.3-1Fixed in 7.1.5-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.177-1~deb11u1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-43500?
The severity of CVE-2026-43500 is critical due to its potential to allow attackers to gain root privileges.
How do I fix CVE-2026-43500?
To fix CVE-2026-43500, you should update to the latest patched version of the Linux kernel.
What are the potential impacts of CVE-2026-43500?
CVE-2026-43500 could lead to unauthorized access and control over affected systems.
Which versions of the Linux kernel are affected by CVE-2026-43500?
CVE-2026-43500 affects multiple versions of the Linux kernel prior to the application of security patches.
How can I verify if my system is vulnerable to CVE-2026-43500?
You can check for CVE-2026-43500 vulnerabilities using system scanning tools or by reviewing your kernel version against known patched releases.