USN-8548-2: Linux kernel vulnerabilities
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - SCSI subsystem; - Thermal drivers; - USB over IP driver; - File systems infrastructure; - Ext4 file system; - Network file system (NFS) server daemon; - SMB network file system; - Tracing infrastructure; - B.A.T.M.A.N. meshing protocol; - Ceph Core library; - DCCP (Datagram Congestion Control Protocol); - IPv4 networking; - IPv6 networking; - Netfilter; - RxRPC session sockets; - X.25 network layer; (CVE-2021-47117, CVE-2021-47202, CVE-2023-52646, CVE-2024-56643, CVE-2026-23455, CVE-2026-31402, CVE-2026-31607, CVE-2026-31637, CVE-2026-31659, CVE-2026-31685, CVE-2026-43011, CVE-2026-43037, CVE-2026-43038, CVE-2026-43383, CVE-2026-43407, CVE-2026-43414, CVE-2026-45988, CVE-2026-46119, CVE-2026-46243)
CSIRTS triage
- What
- Logic flaw in XFRM ESP-in-TCP subsystem (Fragnesia) when handling socket buffer fragments allows privilege escalation and container escape; additional flaws in SCSI, file systems, and networking subsystems.
- Who is affected
- Local users on systems running affected Linux kernel versions; container environments are particularly vulnerable.
- Urgency
- High; Fragnesia enables local privilege escalation and container escape; patch available.
- Action
- Apply USN-8548-2 kernel update immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Linux kernel
Get an email when a new Linux kernel advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://ubuntu.com/security/notices/USN-8548-2
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-435030.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2021-471170.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2021-472020.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2023-526460.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2024-566430.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-234551.3% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 69% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-314020.49% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-316070.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-316370.51% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-316590.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[UPDATE] [medium] Linux Kernel: Vulnerability allows privilege escalationcert-bund
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow Denial of Servicecert-bund
- unknownMultiple vulnerabilities in Ubuntu Linux kernel (August 14, 2026)cert-fr-avis
- unknownUSN-8529-2: Linux kernel vulnerabilitiesubuntu
- unknownUSN-8530-2: Linux kernel (HWE) vulnerabilitiesubuntu
- medium[UPDATE] [medium] Linux Kernel: Multiple Vulnerabilitiescert-bund
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] Linux Kernel: Vulnerability allows gaining administrator rightscert-bund
- unknownUSN-8635-1: Linux kernel (Azure) vulnerabilitiesubuntu
- unknownUSN-8634-1: Linux kernel vulnerabilitiesubuntu
- unknownMultiple vulnerabilities in IBM products (August 07, 2026)cert-fr-avis
More from Ubuntu Security Notices
- unknownUSN-8631-3: Linux kernel (NVIDIA Tegra IGX) vulnerabilities2026-08-13
- unknownUSN-8633-2: Linux kernel vulnerabilities2026-08-13
- unknownUSN-8529-2: Linux kernel vulnerabilities2026-08-13
- unknownUSN-8530-2: Linux kernel (HWE) vulnerabilities2026-08-13
- unknownUSN-8638-1: Axios vulnerabilities2026-08-13