CVE-2026-43503

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker through frag-transfer helpers Two frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail to propagate the SKBFL_SHARED_FRAG bit in skb_shinfo()->flags when moving frags from source to destination. __pskb_copy_fclone() defers the rest of the shinfo metadata to skb_copy_header() after copying frag descriptors, but that helper only carries over gso_{size,segs, type} and never touches skb_shinfo()->flags; skb_shift() moves frag descriptors directly and leaves flags untouched. As a result, the destination skb keeps a reference to the same externally-owned or page-cache-backed pages while reporting skb_has_shared_frag() as false. The mismatch is harmful in any in-place writer that uses skb_has_shared_frag() to decide whether shared pages must be detoured through skb_cow_data(). ESP input is one such writer (esp4.c, esp6.c), and a single nft 'dup to <local>' rule -- or any other nf_dup_ipv4() / xt_TEE caller -- is enough to land a pskb_copy()'d skb in esp_input() with the marker stripped, letting an unprivileged user write into the page cache of a root-owned read-only file via authencesn-ESN stray writes. Set SKBFL_SHARED_FRAG on the destination whenever frag descriptors were actually moved from the source. skb_copy() and skb_copy_expand() share skb_copy_header() too but linearize all paged data into freshly allocated head storage and emerge with nr_frags == 0, so skb_has_shared_frag() returns false on its own; they need no change. The same omission exists in skb_gro_receive() and skb_gro_receive_list(). The former moves the incoming skb's frag descriptors into the accumulator's last sub-skb via two paths (a direct frag-move loop and the head_frag + memcpy path); the latter chains the incoming skb whole onto p's frag_list. Downstream skb_segment() reads only skb_shinfo(p)->flags, and skb_segment_list() reuses each sub-skb's shinfo as the nskb -- both p and lp must carry the marker. The same omission also exists in tcp_clone_payload(), which builds an MTU probe skb by moving frag descriptors from skbs on sk_write_queue into a freshly allocated nskb. The helper falls into the same family and warrants the same fix for consistency; no TCP TX-side in-place writer is currently known to reach a user page through this gap, but a future consumer depending on the marker would regress silently. The same omission exists in skb_segment(): the per-iteration flag merge takes only head_skb's flag, and the inner switch that rebinds frag_skb to list_skb on head_skb-frags exhaustion does not fold the new frag_skb's flag into nskb. Fold frag_skb's flag at both sites so segments drawing frags from frag_list members carry the marker.
References
Link Resource
https://git.kernel.org/stable/c/12401fcfb01f53ccc63ab0a3246570fe8f3105ee Patch
https://git.kernel.org/stable/c/179f1852bdedc300e373e807cc102cd81feff196 Patch
https://git.kernel.org/stable/c/48f6a5356a33dd78e7144ae1faef95ffc990aae0 Patch
https://git.kernel.org/stable/c/989214c66884d70716d83dc1d0bf5e16287bf349 Patch
https://git.kernel.org/stable/c/9bc9d6d6967a2239aa57af2aa53554eddd640d20 Patch
https://git.kernel.org/stable/c/fbeab9555564a1b98e8582cd106dfe46c4606991 Patch
https://git.kernel.org/stable/c/fc6eb39c55e97df2f94ad974b8a5bbcd019da2c8 Patch
https://git.kernel.org/stable/c/ff375cc75f9167168db38e0464a482d5fbc8d81d Patch
https://access.redhat.com/errata/RHSA-2026:19521
https://access.redhat.com/errata/RHSA-2026:19540
https://access.redhat.com/errata/RHSA-2026:19568
https://access.redhat.com/errata/RHSA-2026:19569
https://access.redhat.com/errata/RHSA-2026:19664
https://access.redhat.com/errata/RHSA-2026:19666
https://access.redhat.com/errata/RHSA-2026:19705
https://access.redhat.com/errata/RHSA-2026:19711
https://access.redhat.com/errata/RHSA-2026:19875
https://access.redhat.com/errata/RHSA-2026:20051
https://access.redhat.com/errata/RHSA-2026:20054
https://access.redhat.com/errata/RHSA-2026:20087
https://access.redhat.com/errata/RHSA-2026:20129
https://access.redhat.com/errata/RHSA-2026:20130
https://access.redhat.com/errata/RHSA-2026:20299
https://access.redhat.com/errata/RHSA-2026:20593
https://access.redhat.com/errata/RHSA-2026:21656
https://access.redhat.com/errata/RHSA-2026:21690
https://access.redhat.com/errata/RHSA-2026:21695
https://access.redhat.com/errata/RHSA-2026:21702
https://access.redhat.com/errata/RHSA-2026:23233
https://access.redhat.com/errata/RHSA-2026:23240
https://access.redhat.com/errata/RHSA-2026:23245
https://access.redhat.com/errata/RHSA-2026:23468
https://access.redhat.com/errata/RHSA-2026:23469
https://access.redhat.com/errata/RHSA-2026:23470
https://access.redhat.com/errata/RHSA-2026:23471
https://access.redhat.com/errata/RHSA-2026:24814
https://access.redhat.com/errata/RHSA-2026:25044
https://access.redhat.com/errata/RHSA-2026:33486
https://access.redhat.com/security/cve/CVE-2026-43503
https://bugzilla.redhat.com/show_bug.cgi?id=2480902
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43503.json
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*

History

23 Jul 2026, 11:10

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: net: skbuff: propagar el marcador de fragmento compartido a través de los ayudantes de transferencia de fragmentos Dos ayudantes de transferencia de fragmentos (__pskb_copy_fclone() y skb_shift()) no logran propagar el bit SKBFL_SHARED_FRAG en skb_shinfo()->flags al mover fragmentos del origen al destino. __pskb_copy_fclone() difiere el resto de los metadatos de shinfo a skb_copy_header() después de copiar los descriptores de fragmentos, pero ese ayudante solo transfiere gso_{size,segs,type} y nunca toca skb_shinfo()->flags; skb_shift() mueve los descriptores de fragmentos directamente y deja las banderas intactas. Como resultado, el skb de destino mantiene una referencia a las mismas páginas de propiedad externa o respaldadas por la caché de páginas mientras informa skb_has_shared_frag() como falso. La falta de coincidencia es perjudicial en cualquier escritor in situ que utiliza skb_has_shared_frag() para decidir si las páginas compartidas deben desviarse a través de skb_cow_data(). La entrada ESP es uno de esos escritores (esp4.c, esp6.c), y una única regla nft 'dup to <local>' -- o cualquier otro llamador de nf_dup_ipv4() / xt_TEE -- es suficiente para que un skb copiado con pskb_copy() llegue a esp_input() con el marcador eliminado, permitiendo que un usuario sin privilegios escriba en la caché de páginas de un archivo de solo lectura propiedad de root a través de escrituras errantes de authencesn-ESN. Establecer SKBFL_SHARED_FRAG en el destino siempre que los descriptores de fragmentos se hayan movido realmente del origen. skb_copy() y skb_copy_expand() también comparten skb_copy_header() pero linealizan todos los datos paginados en almacenamiento de cabecera recién asignado y emergen con nr_frags == 0, por lo que skb_has_shared_frag() devuelve falso por sí mismo; no necesitan cambios. La misma omisión existe en skb_gro_receive() y skb_gro_receive_list(). El primero mueve los descriptores de fragmentos del skb entrante al último sub-skb del acumulador a través de dos rutas (un bucle directo de movimiento de fragmentos y la ruta head_frag + memcpy); el segundo encadena el skb entrante completo a la frag_list de p. skb_segment() aguas abajo solo lee skb_shinfo(p)->flags, y skb_segment_list() reutiliza el shinfo de cada sub-skb como el nskb -- tanto p como lp deben llevar el marcador. La misma omisión también existe en tcp_clone_payload(), que construye un skb de sondeo de MTU moviendo descriptores de fragmentos de skbs en sk_write_queue a un nskb recién asignado. El ayudante pertenece a la misma familia y justifica la misma corrección por coherencia; actualmente no se conoce ningún escritor in situ del lado TX de TCP que alcance una página de usuario a través de esta brecha, pero un futuro consumidor que dependa del marcador regresaría silenciosamente. La misma omisión existe en skb_segment(): la fusión de banderas por iteración toma solo la bandera de head_skb, y el switch interno que reasigna frag_skb a list_skb al agotarse los fragmentos de head_skb no incorpora la bandera del nuevo frag_skb en nskb. Incorporar la bandera de frag_skb en ambos sitios para que los segmentos que extraen fragmentos de los miembros de frag_list lleven el marcador.

02 Jul 2026, 12:17

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:19521 -
  • () https://access.redhat.com/errata/RHSA-2026:19540 -
  • () https://access.redhat.com/errata/RHSA-2026:19568 -
  • () https://access.redhat.com/errata/RHSA-2026:19569 -
  • () https://access.redhat.com/errata/RHSA-2026:19664 -
  • () https://access.redhat.com/errata/RHSA-2026:19666 -
  • () https://access.redhat.com/errata/RHSA-2026:19705 -
  • () https://access.redhat.com/errata/RHSA-2026:19711 -
  • () https://access.redhat.com/errata/RHSA-2026:19875 -
  • () https://access.redhat.com/errata/RHSA-2026:20051 -
  • () https://access.redhat.com/errata/RHSA-2026:20054 -
  • () https://access.redhat.com/errata/RHSA-2026:20087 -
  • () https://access.redhat.com/errata/RHSA-2026:20129 -
  • () https://access.redhat.com/errata/RHSA-2026:20130 -
  • () https://access.redhat.com/errata/RHSA-2026:20299 -
  • () https://access.redhat.com/errata/RHSA-2026:20593 -
  • () https://access.redhat.com/errata/RHSA-2026:21656 -
  • () https://access.redhat.com/errata/RHSA-2026:21690 -
  • () https://access.redhat.com/errata/RHSA-2026:21695 -
  • () https://access.redhat.com/errata/RHSA-2026:21702 -
  • () https://access.redhat.com/errata/RHSA-2026:23233 -
  • () https://access.redhat.com/errata/RHSA-2026:23240 -
  • () https://access.redhat.com/errata/RHSA-2026:23245 -
  • () https://access.redhat.com/errata/RHSA-2026:23468 -
  • () https://access.redhat.com/errata/RHSA-2026:23469 -
  • () https://access.redhat.com/errata/RHSA-2026:23470 -
  • () https://access.redhat.com/errata/RHSA-2026:23471 -
  • () https://access.redhat.com/errata/RHSA-2026:24814 -
  • () https://access.redhat.com/errata/RHSA-2026:25044 -
  • () https://access.redhat.com/errata/RHSA-2026:33486 -

30 Jun 2026, 03:19

Type Values Removed Values Added
CWE CWE-664
References
  • () https://access.redhat.com/security/cve/CVE-2026-43503 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2480902 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43503.json -

26 Jun 2026, 18:57

Type Values Removed Values Added
CWE NVD-CWE-noinfo
First Time Linux linux Kernel
Linux
References () https://git.kernel.org/stable/c/12401fcfb01f53ccc63ab0a3246570fe8f3105ee - () https://git.kernel.org/stable/c/12401fcfb01f53ccc63ab0a3246570fe8f3105ee - Patch
References () https://git.kernel.org/stable/c/179f1852bdedc300e373e807cc102cd81feff196 - () https://git.kernel.org/stable/c/179f1852bdedc300e373e807cc102cd81feff196 - Patch
References () https://git.kernel.org/stable/c/48f6a5356a33dd78e7144ae1faef95ffc990aae0 - () https://git.kernel.org/stable/c/48f6a5356a33dd78e7144ae1faef95ffc990aae0 - Patch
References () https://git.kernel.org/stable/c/989214c66884d70716d83dc1d0bf5e16287bf349 - () https://git.kernel.org/stable/c/989214c66884d70716d83dc1d0bf5e16287bf349 - Patch
References () https://git.kernel.org/stable/c/9bc9d6d6967a2239aa57af2aa53554eddd640d20 - () https://git.kernel.org/stable/c/9bc9d6d6967a2239aa57af2aa53554eddd640d20 - Patch
References () https://git.kernel.org/stable/c/fbeab9555564a1b98e8582cd106dfe46c4606991 - () https://git.kernel.org/stable/c/fbeab9555564a1b98e8582cd106dfe46c4606991 - Patch
References () https://git.kernel.org/stable/c/fc6eb39c55e97df2f94ad974b8a5bbcd019da2c8 - () https://git.kernel.org/stable/c/fc6eb39c55e97df2f94ad974b8a5bbcd019da2c8 - Patch
References () https://git.kernel.org/stable/c/ff375cc75f9167168db38e0464a482d5fbc8d81d - () https://git.kernel.org/stable/c/ff375cc75f9167168db38e0464a482d5fbc8d81d - Patch
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*

30 May 2026, 11:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

25 May 2026, 07:16

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/48f6a5356a33dd78e7144ae1faef95ffc990aae0 -

23 May 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-23 12:17

Updated : 2026-07-23 11:10


NVD link : CVE-2026-43503

Mitre link : CVE-2026-43503

CVE.ORG link : CVE-2026-43503


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
NVD-CWE-noinfo CWE-664

Improper Control of a Resource Through its Lifetime