FlawAtlas
Search the atlas
USN-8388-1 Not scored

linux, linux-aws, linux-aws-5.15, linux-aws-fips, linux-fips, linux-gcp, linux-gcp-5.15, linux-gcp-fips, linux-gke, linux-gkeop, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-intel-iot-realtime, linux-intel-iotg, linux-kvm, linux-nvidia, linux-nvidia-tegra, linux-nvidia-tegra-5.15, linux-nvidia-tegra-igx, linux-oracle, linux-raspi, linux-realtime vulnerabilities

It was discovered that the Linux kernel did not properly handle shared page fragments during socket buffer operations, collectively known as Dirty Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the RxRPC networking subsystem when processing paged fragments. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43284, CVE-2026-43500) It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503, CVE-2026-46300) Qualys discovered that a race condition existed in the ptrace subsystem of the Linux kernel when privileged processes are exiting. An unprivileged local attacker could use this issue to expose sensitive information. (CVE-2026-46333) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - RDS protocol; (CVE-2026-43494)

Exploit probability Not scored
Published June 4, 2026
Required by Not available
Last source change July 6, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:22.04:LTS linux

95 explicit affected versions

Ubuntu:22.04:LTS linux-aws

87 explicit affected versions

Ubuntu:22.04:LTS linux-gcp

88 explicit affected versions

Ubuntu:22.04:LTS linux-gke

87 explicit affected versions

Ubuntu:22.04:LTS linux-gkeop

80 explicit affected versions

Ubuntu:22.04:LTS linux-ibm

85 explicit affected versions

Ubuntu:22.04:LTS linux-intel-iotg

75 explicit affected versions

Ubuntu:22.04:LTS linux-kvm

86 explicit affected versions

Ubuntu:22.04:LTS linux-nvidia

72 explicit affected versions

Ubuntu:22.04:LTS linux-nvidia-tegra

45 explicit affected versions

Ubuntu:22.04:LTS linux-nvidia-tegra-igx

41 explicit affected versions

Ubuntu:22.04:LTS linux-oracle

88 explicit affected versions

Ubuntu:22.04:LTS linux-raspi

82 explicit affected versions

Ubuntu:Pro:20.04:LTS linux-aws-5.15

76 explicit affected versions

Ubuntu:Pro:20.04:LTS linux-gcp-5.15

74 explicit affected versions

Ubuntu:Pro:20.04:LTS linux-hwe-5.15

76 explicit affected versions

Ubuntu:Pro:20.04:LTS linux-ibm-5.15

56 explicit affected versions

Ubuntu:Pro:20.04:LTS linux-nvidia-tegra-5.15

34 explicit affected versions

Ubuntu:Pro:FIPS-updates:22.04:LTS linux-aws-fips

50 explicit affected versions

Ubuntu:Pro:FIPS-updates:22.04:LTS linux-fips

52 explicit affected versions

Ubuntu:Pro:FIPS-updates:22.04:LTS linux-gcp-fips

47 explicit affected versions

Ubuntu:Pro:Realtime:22.04:LTS linux-intel-iot-realtime

63 explicit affected versions

Ubuntu:Pro:Realtime:22.04:LTS linux-realtime

86 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities USN-8388-1

It was discovered that the Linux kernel did not properly handle shared page fragments during socket buffer operations, collectively known as Dirty Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the RxRPC networking subsystem when processing paged fragments. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43284, CVE-2026-43500) It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503, CVE-2026-46300) Qualys discovered that a race condition existed in the ptrace subsystem of the Linux kernel when privileged processes are exiting. An unprivileged local attacker could use this issue to expose sensitive information. (CVE-2026-46333) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - RDS protocol; (CVE-2026-43494)

View original source

05 / REFERENCES

Further evidence