Sploitus

CVE-2026-43500

21 known exploits for CVE-2026-43500

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present The DATA-packet handler in rxrpc_input_call_event() and the RESPONSE handler in rxrpc_verify_response() copy the skb to a linear one before calling into the security ops only when skb_cloned() is true. An skb that is not cloned but still carries externally-owned paged fragments (e.g. SKBFL_SHARED_FRAG set by splice() into a UDP socket via __ip_append_data, or a chained skb_has_frag_list()) falls through to the in-place decryption path, which binds the frag pages directly into the AEAD/skcipher SGL via skb_to_sgvec(). Extend the gate to also unshare when skb_has_frag_list() or skb_has_shared_frag() is true. This catches the splice-loopback vector and other externally-shared frag sources while preserving the zero-copy fast path for skbs whose frags are kernel-private (e.g. NIC page_pool RX, GRO). The OOM/trace handling already in place is reused.

Affected products
Linuxmint, Linux Kernel, Red Os, Ubuntu
Linux Linux Kernel
< 6.18.29, 7.0.6, 5.3, 7.1
CVSS 3.1
7.8 HIGH
EPSS
92.9% (100th percentile)
Weakness
CWE-123, CWE-787
NVD status
Modified
Published
2026-05-11
CVE-2026-43500 at NVD
Authoritative description, scoring and affected products

21 known exploits for CVE-2026-43500

Proof-of-concept code and exploit modules indexed by Sploitus

dirtyfrag
2026-07-21 ZeyuanGuoGITHUB
Exploit for Write-what-where Condition in Linux Linux_Kernel
2026-06-30 MadExploitsGITHUB
Exploit for Write-what-where Condition in Linux Linux_Kernel
2026-06-03 1neptuneGITHUB
Exploit for Write-what-where Condition in Linux Linux_Kernel
2026-05-30 K3ysTr0K3RGITHUB
Linux Kernel - Local Privilege Escalation
2026-05-29 nu11secur1tyEXPLOITDB
Linux Kernel - Local Privilege Escalation
2026-05-27 nu11secur1tyEXPLOITDB
Exploit for Write-what-where Condition in Linux Linux_Kernel
2026-05-19 LucasPDinizGITHUB
Exploit for Out-of-bounds Write in Linux Linux_Kernel
2026-05-18 First-JohnGITHUB
DirtyFrag-Linux-Kernel-Local-Privilege-Escalation-Educational-Mirror-
2026-05-15 H4zazGITHUB
Exploit for Write-what-where Condition in Linux Linux_Kernel
2026-05-13 FrosterDLGITHUB
Exploit for Write-what-where Condition in Linux Linux_Kernel
2026-05-11 liamromanis101GITHUB
kernel-exploit-intelligence
2026-05-10 metalx1993GITHUB
centipede
2026-05-09 h0mi3eGITHUB
Exploit for Write-what-where Condition in Linux Linux_Kernel
2026-05-09 metalx1993GITHUB
Exploit for Write-what-where Condition in Linux Linux_Kernel
2026-05-09 haydenjamesGITHUB
Exploit for Write-what-where Condition in Linux Linux_Kernel
2026-05-09 haydenjamesGITHUB
rxkad Page-Cache Write via CVE-2026-43500
2026-05-08 Hyunwoo Kim, Giovanni HewardMETASPLOITRuby
Exploit for Write-what-where Condition in Linux Linux_Kernel
2026-05-08 mym0us3rGITHUB
Exploit for Write-what-where Condition in Linux Linux_Kernel
2026-05-08 lr1458644438GITHUB
Exploit for Incorrect Resource Transfer Between Spheres in Linux Linux_Kernel
2026-05-08 KaraZajacGITHUB
dirtyfrag
2026-05-07 V4belGITHUB