CVE-2026-43284
In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(), so later paths that may modify packet data can first make a private copy. The IPv4/IPv6 datagram append paths did not set this flag when splicing pages into UDP skbs. That leaves an ESP-in-UDP packet made from shared pipe pages looking like an ordinary uncloned nonlinear skb. ESP input then takes the no-COW fast path for uncloned skbs without a frag_list and decrypts in place over data that is not owned privately by the skb. Mark IPv4/IPv6 datagram splice frags with SKBFL_SHARED_FRAG, matching TCP. Also make ESP input fall back to skb_cow_data() when the flag is present, so ESP does not decrypt external-ly backed frags in place. Private nonlinear skb frags still use the existing fast path. This intentionally does not change ESP output. In esp_output_head(), the path that appends the ESP trailer to existing skb tailroom without calling skb_cow_data() is not reachable for nonlinear skbs: skb_tailroom() returns zero when skb->data_len is nonzero, while ESP tailen is positive. Thus ESP output will either use the separate destination-frag path or fall back to skb_cow_data().
EPSS 93.23% · 99.8th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ABB | B&R Industrial Automation GmbH Linux for B&R <=12 | |
| ABB | B&R Industrial Automation GmbH X20EDS410 /all | |
| ABB | B&R Industrial Automation GmbH APROL <APROL-AutoYaST-DVD- V4.4-010.10.260602 |
Timeline
- Apr 20, 2026 CVE Published
- May 8, 2026 PoC Published
- May 8, 2026 PoC Published
- May 8, 2026 PoC Published
- May 8, 2026 PoC Published
- May 8, 2026 PoC Published
- May 8, 2026 PoC Published
- May 8, 2026 PoC Published
- May 8, 2026 PoC Published
- May 8, 2026 PoC Published
- May 8, 2026 PoC Published
- May 8, 2026 PoC Published
References
- https://psirt.abb.com/csaf/2026/sa26p010.json advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-43284 advisory
- https://www.br-automation.com/fileadmin/Cyber_Security_-_Defense_in_Depth_for_BR_Products-bdd37e82.pdf advisory
- https://br-cws-assets.de-fra-1.linodeobjects.com/SA26P010-0ea64434.pdf advisory