Pair of flaws in networking paths (xfrm ESP, RxRPC) that can underpin local escalation on affected kernels. CVSS, CWE, and CPE identifiers are authoritative on NVD.
esp4, esp6, rxrpc) can break IPsec VPNs and RxRPC/AFS traffic—treat as a change-managed trade-off.Recommended reading order: Respond → Distros → Detect → Technical if you still need background.
Ship vendor kernels fast; defer risky module hacks unless approved.
Mechanisms, commits, and researcher FAQs—without exploit steps.
See Technical for chain rationale, Dirty Pipe / Copy Fail context, cited maintainer commits—without exploit walkthroughs.
Proof-of-concept source is referenced only through github.com/V4bel/dirtyfrag for authorized environments.
Immutable references for filings and ticket citations.
Detailed wording remains on each CVE page and NVD; refresh after enrichment updates.
| Field | CVE-2026-43284 | CVE-2026-43500 |
|---|---|---|
| Subsystem | xfrm ESP input / UDP splice skb fragments | RxRPC DATA / RESPONSE handlers |
| CWE (NVD) | CWE-123 (per CISA-ADP listing) | CWE-787 |
| CVSS 3.1 (publishers) | CNA kernel.org 8.8 HIGH vs CISA-ADP 7.8 HIGH — verify on NVD | NIST / CISA-ADP 7.8 HIGH — verify on NVD |
| Where to confirm coverage | Audit each CVE separately: inspect CPE configuration data on CVE-2026-43284 and CVE-2026-43500 NVD listings, then reconcile your fleet against distribution security trackers on the Distros page. | |
Jump to: Respond · Distros · Detect · Sources
rxrpc.ko ships or loads—pairing variants improves coverage across maintained distros. Full narrative on Technical.