CVE-2026-43284: xfrm: esp: avoid in-place decrypt on shared skb frags

Published May 7, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

Other sources

The “Dirty Frag” vulnerability is a chained local privilege escalation (LPE) issue in the Linux kernel that combines flaws in the ESP/XFRM and RXRPC subsystems to allow an unprivileged local attacker to gain root access on major Linux distributions. The attack abuses kernel page-cache manipulation and network protocol handling to overwrite privileged binaries and execute arbitrary code with elevated privileges. Exploitation differs by distribution: the ESP issue affects systems permitting unprivileged user namespaces, while the RXRPC issue impacts distributions with RXRPC enabled, such as Ubuntu. Together, the vulnerabilities provide broad cross-distribution root compromise capability, with mitigations involving disabling vulnerable kernel modules (esp4, esp6, and rxrpc) until upstream patches are fully merged and deployed.

Red Hat

xfrm: esp: avoid in-place decrypt on shared skb frags

Microsoft

Affected Software

12 affected componentsFixes available
Linux Linux kernel
Microsoft azl3 kernel 6.6.137.1-2
Linux Linux kernel>=4.11<5.10.255
Linux Linux kernel>=5.12<5.15.205
Linux Linux kernel>=5.16<6.1.171
Linux Linux kernel>=6.2<6.6.138
Linux Linux kernel>=6.7<6.12.87
Linux Linux kernel>=6.13<6.18.28
Linux Linux kernel>=7.0<7.0.5
IBM API Connect<=V10.0.8.0 - V10.0.8.9
debian/linux<=5.10.223-1
5.10.259-16.1.176-16.12.94-16.12.95-17.1.3-1
debian/linux-6.1
6.1.176-1~deb11u1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/linux to a version that resolves this vulnerability.

    Fixed in 5.10.259-1Fixed in 6.1.176-1Fixed in 6.12.94-1Fixed in 6.12.95-1Fixed in 7.1.3-1
  2. Upgrade

    Upgrade debian/linux-6.1 to a version that resolves this vulnerability.

    Fixed in 6.1.176-1~deb11u1
  3. Upgrade

    Upgrade Linux kernel xfrm: esp to a version that resolves this vulnerability.

    Patch xfrm: esp: avoid in-place decrypt on shared skb frags
  4. Configuration

    Disable the vulnerable ESP IPv4 module (esp4) until upstream patches are fully merged and deployed.

    Linux kernel module esp4 = disabled
  5. Configuration

    Disable the vulnerable ESP IPv6 module (esp6) until upstream patches are fully merged and deployed.

    Linux kernel module esp6 = disabled
  6. Configuration

    Disable the vulnerable RXRPC module (rxrpc) until upstream patches are fully merged and deployed.

    Linux kernel module rxrpc = disabled
  7. Compensating control

    Until upstream patches are fully merged and deployed, mitigate cross-distribution root compromise by disabling vulnerable kernel modules esp4, esp6, and rxrpc (per the cited Dirty Frag mitigation guidance).

Event History

May 7, 2026
Data Sourced
via Red Hat·04:02 PM
DescriptionSeverityAffected Software
May 8, 2026
CVE Published
via MITRE·07:21 AM
Data Sourced
via MITRE·07:21 AM
DescriptionSeverity
News Published
via BleepingComputer·07:45 AM
Data Sourced
via NVD·08:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
May 9, 2026
News Published
via BleepingComputer·07:47 AM
Data Sourced
via Microsoft·08:01 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:01 AM
DescriptionSeverity
May 11, 2026
News Published
via Dark Reading·03:05 PM
News Published
via ZDNet·03:13 PM
News Published
via ZDNet·03:55 PM
May 12, 2026
News Published
via Dark Reading·04:01 PM
May 14, 2026
News Published
via BleepingComputer·07:30 AM
News Published
via BleepingComputer·07:34 AM
May 27, 2026
Exploit Published
via ExploitDB·12:00 AM
Known Exploited
03:17 PM
May 29, 2026
Exploit Published
via ExploitDB·12:00 AM
Jun 3, 2026
Data Sourced
12:00 AM
SeverityWeakness
Jun 22, 2026
Data Sourced
via Launchpad·10:28 PM
Description
Jul 7, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Jul 11, 2026
Data Sourced
via Ubuntu·11:02 AM
RemedyDescriptionSeverityAffected Software
Jul 12, 2026
Data Sourced
via Debian·11:04 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-43284?

CVE-2026-43284 is classified as a medium severity vulnerability.

2

How do I fix CVE-2026-43284?

To fix CVE-2026-43284, upgrade your Linux kernel to the latest stable version that addresses this vulnerability.

3

What systems are affected by CVE-2026-43284?

CVE-2026-43284 affects the Linux kernel when using shared skb fragments.

4

What type of vulnerability is CVE-2026-43284?

CVE-2026-43284 is a memory handling vulnerability related to in-place decryption on shared skb fragments.

5

When was CVE-2026-43284 published?

CVE-2026-43284 was published in the year 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203