Skip to main content

Threats Tagged 'cve-2026-43500'

View all threats tagged with 'cve-2026-43500'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-43500

Threats Tagged 'cve-2026-43500'

Click on any threat for detailed analysis and mitigation recommendations

Red Hat OpenShift Container Platform 4.20.22 addresses two Linux kernel vulnerabilities (CVE-2026-43284 and CVE-2026-43500) known as DirtyFrag that allow local unprivileged attackers to escalate privileges to root on the host. These vulnerabilities affect container environments and have two exploit paths with varying impacts depending on the container runtime and security profiles used. The update fixes these issues and is rated as important by Red Hat with a CVSS score of 7.8 (high severity). Users are advised to upgrade to version 4.20.22 or later to mitigate the risk.

Join the discussion

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present The DATA-packet handler in rxrpc_input_call_event() and the RESPONSE handler in rxrpc_verify_response() copy the skb to a linear one before calling into the security ops only when skb_cloned() is true. An skb that is not cloned but still carries externally-owned paged fragments (e.g. SKBFL_SHARED_FRAG set by splice() into a UDP socket via __ip_append_data, or a chained skb_has_frag_list()) falls through to the in-place decryption path, which binds the frag pages directly into the AEAD/skcipher SGL via skb_to_sgvec(). Extend the gate to also unshare when skb_has_frag_list() or skb_has_shared_frag() is true. This catches the splice-loopback vector and other externally-shared frag sources while preserving the zero-copy fast path for skbs whose frags are kernel-private (e.g. NIC page_pool RX, GRO). The OOM/trace handling already in place is reused.

Join the discussion

CVE-2026-43500 is a vulnerability related to the handling of DATA/RESPONSE packets in the rxrpc protocol when paged fragments are present. The vulnerability affects Microsoft product version 3.0. No CVSS score or detailed technical impact information is provided. There are no known exploits in the wild and no patch or remediation details are available from the provided data.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Tag: cve-2026-43500
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses