{
    "id": "CVE-2026-43500",
    "published": "2026-05-11 08:16:16",
    "last_modified": "2026-08-24 13:18:47",
    "cvss_score": "7.8",
    "cvss_severity": "HIGH",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
    "cwe": "CWE-787",
    "description": "In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Also unshare DATA/RESPONSE packets when paged frags are present\n\nThe DATA-packet handler in rxrpc_input_call_event() and the RESPONSE\nhandler in rxrpc_verify_response() copy the skb to a linear one before\ncalling into the security ops only when skb_cloned() is true.  An skb\nthat is not cloned but still carries externally-owned paged fragments\n(e.g. SKBFL_SHARED_FRAG set by splice() into a UDP socket via\n__ip_append_data, or a chained skb_has_frag_list()) falls through to\nthe in-place decryption path, which binds the frag pages directly into\nthe AEAD/skcipher SGL via skb_to_sgvec().\n\nExtend the gate to also unshare when skb_has_frag_list() or\nskb_has_shared_frag() is true.  This catches the splice-loopback vector\nand other externally-shared frag sources while preserving the\nzero-copy fast path for skbs whose frags are kernel-private (e.g. NIC\npage_pool RX, GRO).  The OOM/trace handling already in place is reused.",
    "epss_score": "0.02257",
    "epss_percentile": "0.82462",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-10-10 18:17:52",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "linux",
            "product": "linux_kernel"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "52591",
            "title": "Linux Kernel -  Local Privilege Escalation",
            "date": "2026-05-29",
            "url": "https://www.exploit-db.com/exploits/52591"
        },
        {
            "source": "exploit-db",
            "ref_id": "52585",
            "title": "Linux Kernel - Local Privilege Escalation",
            "date": "2026-05-27",
            "url": "https://www.exploit-db.com/exploits/52585"
        }
    ],
    "refs_list": [
        "https://git.kernel.org/stable/c/3711382a77342a9a1c3d2e7330dcfc7ea927f568",
        "https://git.kernel.org/stable/c/3eae0f4f9f7206a4801efa5e0235c25bbd5a412c",
        "https://git.kernel.org/stable/c/7c504ffab3efce8f7e4f463b314ae31030bdf18b",
        "https://git.kernel.org/stable/c/aa54b1d27fe0c2b78e664a34fd0fdf7cd1960d71",
        "https://git.kernel.org/stable/c/d45179f8795222ce858770dc619abe51f9d24411",
        "https://access.redhat.com/security/cve/CVE-2026-43500",
        "https://bugzilla.redhat.com/show_bug.cgi?id=2468273",
        "https://github.com/V4bel/dirtyfrag",
        "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43500.json"
    ]
}