FlawAtlas
Search the atlas
USN-8615-1 Not scored

linux, linux-aws, linux-aws-5.4, linux-aws-fips, linux-azure, linux-azure-5.4, linux-azure-fips, linux-bluefield, linux-fips, linux-gcp, linux-gcp-5.4, linux-gcp-fips, linux-hwe-5.4, linux-iot, linux-oracle, linux-oracle-5.4, linux-xilinx-zynqmp vulnerabilities

It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - InfiniBand drivers; - STMicroelectronics network drivers; - NVME drivers; - SCSI subsystem; - USB over IP driver; - Network file system (NFS) server daemon; - SMB network file system; - Tracing infrastructure; - B.A.T.M.A.N. meshing protocol; - Ethernet bridge; - Ceph Core library; - IPv4 networking; - IPv6 networking; - Netfilter; - RxRPC session sockets; - X.25 network layer; (CVE-2026-23272, CVE-2026-23455, CVE-2026-31402, CVE-2026-31418, CVE-2026-31607, CVE-2026-31637, CVE-2026-31649, CVE-2026-31659, CVE-2026-31682, CVE-2026-31685, CVE-2026-43011, CVE-2026-43037, CVE-2026-43038, CVE-2026-43117, CVE-2026-43383, CVE-2026-43407, CVE-2026-43414, CVE-2026-45988, CVE-2026-46043, CVE-2026-46119, CVE-2026-46135, CVE-2026-46243)

Exploit probability Not scored
Published July 28, 2026
Required by Not available
Last source change July 28, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:Pro:18.04:LTS linux-aws-5.4

107 explicit affected versions

Ubuntu:Pro:18.04:LTS linux-azure-5.4

103 explicit affected versions

Ubuntu:Pro:18.04:LTS linux-gcp-5.4

110 explicit affected versions

Ubuntu:Pro:18.04:LTS linux-hwe-5.4

119 explicit affected versions

Ubuntu:Pro:18.04:LTS linux-oracle-5.4

109 explicit affected versions

Ubuntu:Pro:20.04:LTS linux

131 explicit affected versions

Ubuntu:Pro:20.04:LTS linux-aws

122 explicit affected versions

Ubuntu:Pro:20.04:LTS linux-azure

115 explicit affected versions

Ubuntu:Pro:20.04:LTS linux-bluefield

79 explicit affected versions

Ubuntu:Pro:20.04:LTS linux-gcp

123 explicit affected versions

Ubuntu:Pro:20.04:LTS linux-iot

52 explicit affected versions

Ubuntu:Pro:20.04:LTS linux-oracle

120 explicit affected versions

Ubuntu:Pro:20.04:LTS linux-xilinx-zynqmp

55 explicit affected versions

Ubuntu:Pro:FIPS-updates:20.04:LTS linux-aws-fips

75 explicit affected versions

Ubuntu:Pro:FIPS-updates:20.04:LTS linux-azure-fips

71 explicit affected versions

Ubuntu:Pro:FIPS-updates:20.04:LTS linux-fips

90 explicit affected versions

Ubuntu:Pro:FIPS-updates:20.04:LTS linux-gcp-fips

76 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities USN-8615-1

It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - InfiniBand drivers; - STMicroelectronics network drivers; - NVME drivers; - SCSI subsystem; - USB over IP driver; - Network file system (NFS) server daemon; - SMB network file system; - Tracing infrastructure; - B.A.T.M.A.N. meshing protocol; - Ethernet bridge; - Ceph Core library; - IPv4 networking; - IPv6 networking; - Netfilter; - RxRPC session sockets; - X.25 network layer; (CVE-2026-23272, CVE-2026-23455, CVE-2026-31402, CVE-2026-31418, CVE-2026-31607, CVE-2026-31637, CVE-2026-31649, CVE-2026-31659, CVE-2026-31682, CVE-2026-31685, CVE-2026-43011, CVE-2026-43037, CVE-2026-43038, CVE-2026-43117, CVE-2026-43383, CVE-2026-43407, CVE-2026-43414, CVE-2026-45988, CVE-2026-46043, CVE-2026-46119, CVE-2026-46135, CVE-2026-46243)

View original source

05 / REFERENCES

Further evidence