CVE-2026-43284
Description
Important: kernel security update
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2026-19225.html
Vendor advisory: alma — https://bugzilla.redhat.com/2461763
Vendor advisory: alma — https://bugzilla.redhat.com/2460538
Vendor advisory: alma — https://bugzilla.redhat.com/2436779
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2026-A005.html
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2026-16206.html
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2026-16196.html
Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2026:16196
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2026-A007.html
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2026-A004.html
Vendor advisory: alma — https://bugzilla.redhat.com/show_bug.cgi?id=2467771
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2026-16195.html
Vendor advisory: alma — https://bugzilla.redhat.com/2467771
Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2026:16195
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2026-43284
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2026-43284.html
Vendor advisory: 416baaa9-dc9f-4396-8d5f-8c081fb06d67 — https://git.kernel.org/stable/c/b54edf1e9a3fd3491bdcb82a21f8d21315271e0d
Vendor advisory: 416baaa9-dc9f-4396-8d5f-8c081fb06d67 — https://git.kernel.org/stable/c/ab8b995323e5237041472d07e5055f5f7dcdf15b
Vendor advisory: 416baaa9-dc9f-4396-8d5f-8c081fb06d67 — https://git.kernel.org/stable/c/a6cb440f274a22456ef3e86b457344f1678f38f9
Vendor advisory: 416baaa9-dc9f-4396-8d5f-8c081fb06d67 — https://git.kernel.org/stable/c/71a1d9d985d26716f74d21f18ee8cac821b06e97
Vendor advisory: 416baaa9-dc9f-4396-8d5f-8c081fb06d67 — https://git.kernel.org/stable/c/5d55c7336f8032d434adcc5fab987ccc93a44aec
Vendor advisory: 416baaa9-dc9f-4396-8d5f-8c081fb06d67 — https://git.kernel.org/stable/c/52646cbd00e765a6db9c3afe9535f26218276034
Vendor advisory: 416baaa9-dc9f-4396-8d5f-8c081fb06d67 — https://git.kernel.org/stable/c/50ed1e7873100f77abad20fd31c51029bc49cd03
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2026:19568
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2026:19225
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2026:16206
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| rhel | 9 | fixed | |
| sles | affected | | |
| debian | bookworm | fixed | 6.1.170-3 |
| debian | bullseye | fixed | 5.10.251-4 |
| debian | forky | fixed | 7.0.4-1 |
| debian | sid | fixed | 7.0.4-1 |
| debian | trixie | fixed | 6.12.86-1 |
| linux-kernel | affected | 5.10.255 |
References
- https://access.redhat.com/errata/RHSA-2026:16206
- https://access.redhat.com/errata/RHSA-2026:19225
- https://access.redhat.com/errata/RHSA-2026:19568
- https://git.kernel.org/stable/c/50ed1e7873100f77abad20fd31c51029bc49cd03
- https://git.kernel.org/stable/c/52646cbd00e765a6db9c3afe9535f26218276034
- https://git.kernel.org/stable/c/5d55c7336f8032d434adcc5fab987ccc93a44aec
- https://git.kernel.org/stable/c/71a1d9d985d26716f74d21f18ee8cac821b06e97
- https://git.kernel.org/stable/c/8253aab4659ca16116b522203c2a6b18dccacea7
- https://git.kernel.org/stable/c/a6cb440f274a22456ef3e86b457344f1678f38f9
- https://git.kernel.org/stable/c/ab8b995323e5237041472d07e5055f5f7dcdf15b
- https://git.kernel.org/stable/c/b54edf1e9a3fd3491bdcb82a21f8d21315271e0d
- https://git.kernel.org/stable/c/f4c50a4034e62ab75f1d5cdd191dd5f9c77fdff4
- https://git.kernel.org/stable/c/fe785bb3a8096dffcc4048a85cd0c83337eeecad
- http://www.openwall.com/lists/oss-security/2026/05/08/7
- http://www.openwall.com/lists/oss-security/2026/05/13/6
- http://www.openwall.com/lists/oss-security/2026/05/14/2
- http://www.openwall.com/lists/oss-security/2026/05/14/4
- https://www.vicarius.io/vsociety/posts/cve-2026-43284-detection-script-dirty-frag-linux-kernel-local-privilege-escalation
- https://www.vicarius.io/vsociety/posts/cve-2026-43284-mitigation-script-dirty-frag-linux-kernel-local-privilege-escalation
- https://github.com/V4bel/dirtyfrag
- https://www.suse.com/security/cve/CVE-2026-43284.html
- https://security-tracker.debian.org/tracker/CVE-2026-43284
- https://access.redhat.com/errata/RHSA-2026:16195
- https://bugzilla.redhat.com/2467771
- https://errata.almalinux.org/8/ALSA-2026-16195.html
CWEs
CWE-123
Verify integrity in audit chain (admin only). AS-IS.