LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-43284

CVE-2026-43284 - Vulnerability Analysis

HighCVSS: 7.8

Last Updated: May 8, 2026

Linux Kernel - Memory Corruption via In-Place ESP Decryption

Published: May 8, 2026Updated: May 8, 2026PoC Available

Overview

Linux kernel contains an in-place decryption vulnerability in xfrm ESP due to missing SKBFL_SHARED_FRAG flag on shared skb fragments in IPv4/IPv6 UDP datagram splicing, letting attackers cause data corruption or memory issues, exploit requires crafted ESP-in-UDP packets with shared pipe pages.

Severity & Score

Severity: High
CVSS Score: 7.8

Impact

Attackers can cause data corruption or memory issues by triggering in-place decryption on shared skb fragments, potentially leading to denial of service or information disclosure.

Mitigation

Update to the latest Linux kernel version containing the fix for SKBFL_SHARED_FRAG flag handling in xfrm ESP.

Details

CVE ID
CVE-2026-43284
Severity
High
CVSS Score
7.8
Type
undefined
Status
modified

CWE

  • CWE-123

CVSS Metrics

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H