FlawAtlas
Search the atlas
USN-8389-1 Not scored

linux, linux-aws, linux-aws-fips, linux-azure, linux-azure-5.4, linux-azure-fips, linux-bluefield, linux-fips, linux-gcp, linux-gcp-5.4, linux-gcp-fips, linux-iot, linux-kvm, linux-oracle, linux-oracle-5.4, linux-xilinx-zynqmp vulnerabilities

It was discovered that the Linux kernel did not properly handle shared page fragments during socket buffer operations, collectively known as Dirty Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the RxRPC networking subsystem when processing paged fragments. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43284, CVE-2026-43500) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - RDS protocol; (CVE-2026-43494)

Exploit probability Not scored
Published June 4, 2026
Required by Not available
Last source change July 6, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:Pro:18.04:LTS linux-azure-5.4

102 explicit affected versions

Ubuntu:Pro:18.04:LTS linux-gcp-5.4

109 explicit affected versions

Ubuntu:Pro:18.04:LTS linux-oracle-5.4

108 explicit affected versions

Ubuntu:Pro:20.04:LTS linux

130 explicit affected versions

Ubuntu:Pro:20.04:LTS linux-aws

121 explicit affected versions

Ubuntu:Pro:20.04:LTS linux-azure

114 explicit affected versions

Ubuntu:Pro:20.04:LTS linux-bluefield

78 explicit affected versions

Ubuntu:Pro:20.04:LTS linux-gcp

122 explicit affected versions

Ubuntu:Pro:20.04:LTS linux-iot

51 explicit affected versions

Ubuntu:Pro:20.04:LTS linux-kvm

117 explicit affected versions

Ubuntu:Pro:20.04:LTS linux-oracle

119 explicit affected versions

Ubuntu:Pro:20.04:LTS linux-xilinx-zynqmp

54 explicit affected versions

Ubuntu:Pro:FIPS-updates:20.04:LTS linux-aws-fips

74 explicit affected versions

Ubuntu:Pro:FIPS-updates:20.04:LTS linux-azure-fips

70 explicit affected versions

Ubuntu:Pro:FIPS-updates:20.04:LTS linux-fips

89 explicit affected versions

Ubuntu:Pro:FIPS-updates:20.04:LTS linux-gcp-fips

75 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities USN-8389-1

It was discovered that the Linux kernel did not properly handle shared page fragments during socket buffer operations, collectively known as Dirty Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the RxRPC networking subsystem when processing paged fragments. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43284, CVE-2026-43500) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - RDS protocol; (CVE-2026-43494)

View original source

05 / REFERENCES

Further evidence