CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

USN-8617-1: Linux kernel (KVM) vulnerabilities

unknownCVE-2026-43503CVE-2026-23272CVE-2026-23455CVE-2026-31418CVE-2026-31607CVE-2026-31637
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - InfiniBand drivers; - STMicroelectronics network drivers; - SCSI subsystem; - USB over IP driver; - SMB network file system; - Tracing infrastructure; - B.A.T.M.A.N. meshing protocol; - Ethernet bridge; - Ceph Core library; - IPv4 networking; - IPv6 networking; - Netfilter; - RxRPC session sockets; - X.25 network layer; (CVE-2026-23272, CVE-2026-23455, CVE-2026-31418, CVE-2026-31607, CVE-2026-31637, CVE-2026-31649, CVE-2026-31659, CVE-2026-31682, CVE-2026-31685, CVE-2026-43011, CVE-2026-43038, CVE-2026-43117, CVE-2026-43383, CVE-2026-43407, CVE-2026-43414, CVE-2026-46043, CVE-2026-46243)

CSIRTS triage

What
A logic flaw in the Linux kernel could allow local attackers to escalate privileges or escape a container.
Who is affected
Users of the Linux kernel are affected.
Urgency
Remediation is necessary, but severity is currently unknown.
Action
Update to the latest version of the Linux kernel.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Linux kernel

Get an email when a new Linux kernel advisory drops — max one per day, one-click unsubscribe.

Details

Source
Ubuntu Security Notices (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-07-28
Exploitation
Not in CISA KEV at last sync

Original advisory: https://ubuntu.com/security/notices/USN-8617-1

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-43503coverage & exploitation statusNVD · CVE.org
CVE-2026-23272coverage & exploitation statusNVD · CVE.org
CVE-2026-23455coverage & exploitation statusNVD · CVE.org
CVE-2026-31418coverage & exploitation statusNVD · CVE.org
CVE-2026-31607coverage & exploitation statusNVD · CVE.org
CVE-2026-31637coverage & exploitation statusNVD · CVE.org
CVE-2026-31649coverage & exploitation statusNVD · CVE.org
CVE-2026-31659coverage & exploitation statusNVD · CVE.org
CVE-2026-31682coverage & exploitation statusNVD · CVE.org
CVE-2026-31685coverage & exploitation statusNVD · CVE.org
CVE-2026-43011coverage & exploitation statusNVD · CVE.org
CVE-2026-43038coverage & exploitation statusNVD · CVE.org
CVE-2026-43117coverage & exploitation statusNVD · CVE.org
CVE-2026-43383coverage & exploitation statusNVD · CVE.org
CVE-2026-43407coverage & exploitation statusNVD · CVE.org
CVE-2026-43414coverage & exploitation statusNVD · CVE.org
CVE-2026-46043coverage & exploitation statusNVD · CVE.org
CVE-2026-46243coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Ubuntu Security Notices