rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
Published May 11, 2026
7.8
HIGHCVSS 3.1
EPSS 2.26%
Description
The DATA-packet handler in rxrpc_input_call_event() and the RESPONSE handler in rxrpc_verify_response() copy the skb to a linear one before calling into the security ops only when skb_cloned() is true. An skb that is not cloned but still carries externally-owned paged fragments (e.g. SKBFL_SHARED_FRAG set by splice() into a UDP socket via __ip_append_data, or a chained skb_has_frag_list()) falls through to the in-place decryption path, which binds the frag pages directly into the AEAD/skcipher SGL via skb_to_sgvec().
Extend the gate to also unshare when skb_has_frag_list() or skb_has_shared_frag() is true. This catches the splice-loopback vector and other externally-shared frag sources while preserving the zero-copy fast path for skbs whose frags are kernel-private (e.g. NIC page_pool RX, GRO). The OOM/trace handling already in place is reused.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.3StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.3
- Version 6.12.88StatusunaffectedConstraints<=6.12.*
- Version 6.18.29StatusunaffectedConstraints<=6.18.*
- Version 6.6.140StatusunaffectedConstraints<=6.6.*
- Version 7.0.6StatusunaffectedConstraints<=7.0.*
- Version 7.1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||
| Linux | Linux | affected |
|
- > 5.3 · < 6.18.29
- ≥ 6.19 · < 7.0.6
- 5.3
- 5.3
- 5.3
- 7.1
- 7.1
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 10
libkrun
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 10 | libkrun | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue is classified as Important, rather than Critical severity, because exploitation requires local access to the system. A low-privileged local attacker can exploit this flaw in the Linux kernel's RxRPC subsystem to gain root privileges by overwriting sensitive system files. Exploitation does not require user interaction, potentially resulting in full compromise of confidentiality, integrity, and availability. While the kernel source RPM for Red Hat Enterprise Linux 9 and 10 includes the `rxrpc` module in its build configuration, the binary RPMs that provide this module are not shipped or supported by Red Hat. The module is not installed by default and is not included in any other kernel binary package. For OpenShift Container Platform 4, the RPMs are not included in Red Hat Enterprise Linux CoreOS (RHCOS) images and is not installable through any supported cluster workflow.
Red Hat mitigation
See the security bulletin for a detailed mitigation procedure.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed May 11, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
May–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.26% (0.02257) | 82.33th | v5 (v2026.06.15) |
| Sep 20, 2026 | 92.86% (0.92855) | 99.83th | v5 (v2026.06.15) |
| Jun 23, 2026 | 92.64% (0.92641) | 99.81th | v5 (v2026.06.15) |
| Jun 15, 2026 | 93.99% (0.93994) | 99.83th | v5 (v2026.06.15) |
| Jun 12, 2026 | 33.66% (0.33658) | 97.06th | v4 (v2025.03.14) |
| Jun 5, 2026 | 40.27% (0.40266) | 97.43th | v4 (v2025.03.14) |
| Jun 3, 2026 | 43.54% (0.43539) | 97.58th | v4 (v2025.03.14) |
| May 30, 2026 | 40.27% (0.40266) | 97.42th | v4 (v2025.03.14) |
| May 28, 2026 | 27.00% (0.26995) | 96.45th | v4 (v2025.03.14) |
| May 21, 2026 | 1.71% (0.01711) | 82.56th | v4 (v2025.03.14) |
| May 11, 2026 | 0.01% (0.00013) | 2.26th | v4 (v2025.03.14) |
References (12)
- https://access.redhat.com/security/cve/CVE-2026-43500 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2468273 Issue Tracking
- https://git.kernel.org/stable/c/3711382a77342a9a1c3d2e7330dcfc7ea927f568
- https://git.kernel.org/stable/c/3eae0f4f9f7206a4801efa5e0235c25bbd5a412c Patch
- https://git.kernel.org/stable/c/7c504ffab3efce8f7e4f463b314ae31030bdf18b
- https://git.kernel.org/stable/c/aa54b1d27fe0c2b78e664a34fd0fdf7cd1960d71 Patch
- https://git.kernel.org/stable/c/d45179f8795222ce858770dc619abe51f9d24411 Patch
- https://github.com/V4bel/dirtyfrag exploit
- https://lore.kernel.org/linux-cve-announce/2026051149-CVE-2026-43500-60d6@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-43500
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43500.json
- https://www.cve.org/CVERecord?id=CVE-2026-43500
Change history (0)
No recorded changes yet.