CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-31637

highcovered by 27 sourcesfirst seen 2026-07-09
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - InfiniBand drivers; - SCSI subsystem; - Thermal drivers; - USB over IP driver; - Network file system (NFS) server daemon; - SMB network file system; - Tracing infrastructure; - B.A.T.M.A.N. meshing protocol; - Ethernet bridge; - Ceph Core library; - DCCP (Datagram Congestion Control Protocol); - IPv4 networking; - IPv6 networking; - Netfilter; - RxRPC session sockets; - X.25 network layer; (CVE-2021-47202, CVE-2024-56643, CVE-2026-23272, CVE-2026-23455, CVE-2026-31402, CVE-2026-31607, CVE-2026-31637, CVE-2026-31659, CVE-2026-31682, CVE-2026-31685, CVE-2026-43011, CVE-2026-43037, CVE-2026-43038, CVE-2026-43383, CVE-2026-43407, CVE-2026-43414, CVE-2026-45988, CVE-2026-46043, CVE-2026-46119, CVE-2026-46243)

CSIRTS triage

What
Logic flaw in XFRM ESP-in-TCP subsystem (Fragnesia) when handling socket buffer fragments allows privilege escalation and container escape; additional flaws in multiple subsystems.
Who is affected
Local users on systems running affected Linux kernel versions; container environments are particularly vulnerable.
Urgency
High; Fragnesia enables local privilege escalation and container escape; patch available.
Action
Apply USN-8529-2 kernel update immediately.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-31637

Get an email if CVE-2026-31637 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (27)

External references

NVD record for CVE-2026-31637

CVE.org record

Embed the live status

CVE-2026-31637 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-31637 status](https://www.csirts.com/badge/CVE-2026-31637)](https://www.csirts.com/cve/CVE-2026-31637)