Priority reviewHigh

CVE-2026-43284

Linux Linux, NVIDIA for RHEL 10, Red Hat Enterprise Linux 10

In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(), so later paths that may modify packet data can first make a private copy. The IPv4/IPv6 datagram append paths did not set this flag when splicing pages into UDP skbs. That leaves an ESP-in-UDP packet made from shared pipe pages looking like an ordinary uncloned nonlinear skb. ESP input then takes the no-COW fast path for uncloned skbs...

CVSS
8.8
EPSS
93.2%
99.8% percentile
CISA KEV
Not listed
Published
2026.05.08
PRIORITY ASSESSMENT

Priority review

FIRST EPSS indicates an elevated probability of exploitation.

Known exploitationNot established by KEV
Exploit probability93.2%
Technical severityCVSS 8.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(), so later paths that may modify packet data can first make a private copy. The IPv4/IPv6 datagram append paths did not set this flag when splicing pages into UDP skbs. That leaves an ESP-in-UDP packet made from shared pipe pages looking like an ordinary uncloned nonlinear skb. ESP input then takes the no-COW fast path for uncloned skbs...

Affected product and versions

Product
Linux Linux, NVIDIA for RHEL 10, Red Hat Enterprise Linux 10
Affected versions
>= cac2661c53f35cbe651bef9b07026a5a05ab8ce0 < a6cb440f274a22456ef3e86b457344f1678f38f9, >= cac2661c53f35cbe651bef9b07026a5a05ab8ce0 < ab8b995323e5237041472d07e5055f5f7dcdf15b, >= cac2661c53f35cbe651bef9b07026a5a05ab8ce0 < fe785bb3a8096dffcc4048a85cd0c83337eeecad, >= cac2661c53f35cbe651bef9b07026a5a05ab8ce0 < 5d55c7336f8032d434adcc5fab987ccc93a44aec, >= cac2661c53f35cbe651bef9b07026a5a05ab8ce0 < 8253aab4659ca16116b522203c2a6b18dccacea7, >= cac2661c53f35cbe651bef9b07026a5a05ab8ce0 < 50ed1e7873100f77abad20fd31c51029bc49cd03, >= cac2661c53f35cbe651bef9b07026a5a05ab8ce0 < b54edf1e9a3fd3491bdcb82a21f8d21315271e0d, >= cac2661c53f35cbe651bef9b07026a5a05ab8ce0 < 71a1d9d985d26716f74d21f18ee8cac821b06e97, >= cac2661c53f35cbe651bef9b07026a5a05ab8ce0 < 52646cbd00e765a6db9c3afe9535f26218276034, >= cac2661c53f35cbe651bef9b07026a5a05ab8ce0 < f4c50a4034e62ab75f1d5cdd191dd5f9c77fdff4, >= 4.11, >= V3.1.6, >= V3.1.5, >= 4.11 < 5.10.255, >= 5.12 < 5.15.205, >= 5.16 < 6.1.171, >= 6.2 < 6.6.138, >= 6.7 < 6.12.87, >= 6.13 < 6.18.28, >= 7.0 < 7.0.5
Fixed versions
5.10.255, 5.15.205, 6.1.171, 6.6.138, 6.12.87, 6.18.28, 7.0.5

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, NVIDIA for RHEL 10, Red Hat Enterprise Linux 10 and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE
CWE-123
CVE-2026-43284 — Linux Linux, NVIDIA for RHEL 10, Red Hat Enterprise Linux 10 | SECUFOCUS NOW