← Back to browse · API

CVE-2026-43500

Severity
HIGH
CVSS
7.8
EPSS
0.92855
Risk score
63.7
CISA KEV
No
PoC
Yes
Published
2026-05-11
Modified
2026-08-05
First seen
2026-08-06
Aliases
CNVD-2026-21360, EUVD-2026-29037, GHSA-8P2W-G92W-F4X3
Products
Linux Linux kernel 5.3, Linux Linux kernel 5.3 rc7, Linux Linux kernel 5.3 rc8, Linux Linux kernel 7.1 rc1, Linux Linux kernel 7.1 rc2, Linux Linux kernel >5.3,<6.18.29, Linux Linux kernel >=6.19,<7.0.6, Linux:Linux 5.3, Linux:Linux d0d5c0cd1e711c98703f3544c1e6fc1372898de5 <3711382a77342a9a1c3d2e7330dcfc7ea927f568, Linux:Linux d0d5c0cd1e711c98703f3544c1e6fc1372898de5 <3eae0f4f9f7206a4801efa5e0235c25bbd5a412c, Linux:Linux d0d5c0cd1e711c98703f3544c1e6fc1372898de5 <7c504ffab3efce8f7e4f463b314ae31030bdf18b, Linux:Linux d0d5c0cd1e711c98703f3544c1e6fc1372898de5 <aa54b1d27fe0c2b78e664a34fd0fdf7cd1960d71, Linux:Linux d0d5c0cd1e711c98703f3544c1e6fc1372898de5 <d45179f8795222ce858770dc619abe51f9d24411, Linux:Linux patch: 0, Linux:Linux patch: 6.12.88, Linux:Linux patch: 6.18.29, Linux:Linux patch: 6.6.140, Linux:Linux patch: 7.0.6, Linux:Linux patch: 7.1, unix
Sources
cnvd CNVD-2026-21360
github fbf68038fee5f4fa53520629|CVE-2026-43500
euvd EUVD-2026-29037
packetstorm bd2236092be59388bfdefee2|CVE-2026-43500
github dafe85faefa240ce615dc5b3|CVE-2026-43500
github e1fc6a165baedbded9e22b6c|CVE-2026-43500

Description

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present The DATA-packet handler in rxrpc_input_call_event() and the RESPONSE handler in rxrpc_verify_response() copy the skb to a linear one before calling into the security ops only when skb_cloned() is true. An skb that is not cloned but still carries externally-owned paged fragments (e.g. SKBFL_SHARED_FRAG set by splice() into a UDP socket via __ip_append_data, or a chained skb_has_frag_list()) falls through to the in-place decryption path, which binds the frag pages directly into the AEAD/skcipher SGL via skb_to_sgvec(). Extend the gate to also unshare when skb_has_frag_list() or skb_has_shared_frag() is true. This catches the splice-loopback vector and other externally-shared frag sources while preserving the zero-copy fast path for skbs whose frags are kernel-private (e.g. NIC page_pool RX, GRO). The OOM/trace handling already in place is reused.

References