Security News

Cybersecurity news aggregator

🔓
HIGH Vulnerabilities Ubuntu Security

USN-8615-1: Linux kernel vulnerabilities

A logic flaw in the Linux kernel's XFRM ESP-in-TCP subsystem, known as Fragnesia (CVE-2026-43503, CVSS 8.8 HIGH), allows a local attacker to escalate privileges or escape a container. Affected kernel versions range from 3.9 to 6.12.91 across multiple major branches, with fixes available in specific versions like 5.10.257, 6.1.174, and 6.12.91. The update also addresses numerous other high-severity vulnerabilities across multiple subsystems, including InfiniBand, NVME, Netfilter, and networking stacks.
Read Full Article →

It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - InfiniBand drivers; - STMicroelectronics network drivers; - NVME drivers; - SCSI subsystem; - USB over IP driver; - Network file system (NFS) server daemon; - SMB network file system; - Tracing infrastructure; - B.A.T.M.A.N. meshing protocol; - Ethernet bridge; - Ceph Core library; - IPv4 networking; - IPv6 networking; - Netfilter; - RxRPC session sockets; - X.25 network layer; (CVE-2026-23272, CVE-2026-23455, CVE-2026-31402, CVE-2026-31418, CVE-2026-31607, CVE-2026-31637, CVE-2026-31649, CVE-2026-31659, CVE-2026-31682, CVE-2026-31685, CVE-2026-43011, CVE-2026-43037, CVE-2026-43038, CVE-2026-43117, CVE-2026-43383, CVE-2026-43407, CVE-2026-43414, CVE-2026-45988, CVE-2026-46043, CVE-2026-46119, CVE-2026-46135, CVE-2026-46243)

Share this article