CVE-2026-43284HIGH 8.8EPSS p99.8%

CVE-2026-43284CVE-2026-43284

linux / linux_kernel

Description

In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(), so later paths that may modify packet data can first make a private copy. The IPv4/IPv6 datagram append paths did not set this flag when splicing pages into UDP skbs. That leaves an ESP-in-UDP packet made from shared pipe pages looking like an ordinary uncloned nonlinear skb. ESP input then takes the no-COW fast path for uncloned skbs without a frag_list and decrypts in place over data that is not owned privately by the skb. Mark IPv4/IPv6 datagram splice frags with SKBFL_SHARED_FRAG, matching TCP. Also make ESP input fall back to skb_cow_data() when the flag is present, so ESP does not decrypt externally backed frags in place. Private nonlinear skb frags still use the existing fast path. This intentionally does not change E

Scoring

CVSS 3.18.8 (HIGH)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS93.23% probability of exploitation · percentile 99.8% · 2026-07-29T12:03:07Z
Published2026-05-08
Last modified2026-07-15

Underlying weaknesses· 1

CWE-123

References

  1. https://git.kernel.org/stable/c/50ed1e7873100f77abad20fd31c51029bc49cd03
  2. https://git.kernel.org/stable/c/52646cbd00e765a6db9c3afe9535f26218276034
  3. https://git.kernel.org/stable/c/5d55c7336f8032d434adcc5fab987ccc93a44aec
  4. https://git.kernel.org/stable/c/71a1d9d985d26716f74d21f18ee8cac821b06e97
  5. https://git.kernel.org/stable/c/8253aab4659ca16116b522203c2a6b18dccacea7
  6. https://git.kernel.org/stable/c/a6cb440f274a22456ef3e86b457344f1678f38f9
  7. https://git.kernel.org/stable/c/ab8b995323e5237041472d07e5055f5f7dcdf15b
  8. https://git.kernel.org/stable/c/b54edf1e9a3fd3491bdcb82a21f8d21315271e0d

1

TypeTargetConfidenceTier
WeaknessWrite-what-where Conditioncwe-1230%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-46323
CVE
CVE-2026-46322
CVE
CVE-2026-43039
CVE
CVE-2026-43452
CVE
CVE-2026-43093
CVE
CVE-2026-31664
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.