CVE-2026-46300

Linux kernel (Azure) vulnerabilities

Description

A flaw was found in the Linux kernel's XFRM ESP-in-TCP subsystem. Unsafe in-place cryptographic processing allows a low-privileged local attacker to write arbitrary bytes into the page cache of read-only files, including sensitive system files. An attacker can exploit this to overwrite privileged binaries and gain root privileges.

Metrics

Severity
high
PoC (publicly reported)
7.8
Source: nvd-v3
95.1 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
9.3 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2026-06-16 22:30 UTC

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-09-08 09:18 UTC· 416baaa9-dc9f-4396-8d5f-8c081fb06d67
    • Reference: https://git.kernel.org/stable/c/2f2b16022a2e10ca7bccfb98db5ed2ec0f72641c
    • Reference: https://git.kernel.org/stable/c/3599e6b3cc1ada96883d496a50a210d3afbb6987
    • Reference: https://git.kernel.org/stable/c/3884358a9286b17f389a72b1426fc4547c23c111
    • Reference: https://git.kernel.org/stable/c/3bd9e113d50034db99d7ef69fd8e5242d15e414a
  2. CVE Modified2026-09-08 09:18 UTC· af854a3a-2127-422b-91ae-364da2661108
    • Reference: http://www.openwall.com/lists/oss-security/2026/05/13/5
    • Reference: http://www.openwall.com/lists/oss-security/2026/05/21/11
    • Reference: http://www.openwall.com/lists/oss-security/2026/05/21/12
    • Reference: http://www.openwall.com/lists/oss-security/2026/05/21/13
  3. CVE Modified2026-09-08 09:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHBA-2026:20032
    • Reference: https://access.redhat.com/errata/RHSA-2026:19521
    • Reference: https://access.redhat.com/errata/RHSA-2026:19540
    • Reference: https://access.redhat.com/errata/RHSA-2026:19568
  4. CVE Modified2026-09-08 09:18 UTC· 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/46xxx/CVE-2026-46300.json">CVE-2026-46300</a>
    • Reference: https://cert-portal.siemens.com/productcert/html/ssa-019113.html
    • Reference: https://cert-portal.siemens.com/productcert/html/ssa-082556.html
    • Reference: https://cert-portal.siemens.com/productcert/html/ssa-019113.html
  5. CVE Translated2026-07-23 11:10 UTC· nvd@nist.gov
    • Translation: Title: Linux, Description: En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: net: skbuff: preservar el marcador de fragmento compartido durante la coalescencia skb_try_coalesce() puede adjuntar fragmentos paginados de @from a @to. Si @from tiene SKBFL_SHARED_FRAG establecido, el skb @to resultante puede contener los mismos fragmentos de propiedad externa o respaldados por la caché de páginas, pero el marcador de fragmento compartido se pierde actualmente. Eso rompe el invariante en el que confían los escritores posteriores in situ. En particular, la entrada de ESP comprueba skb_has_shared_frag() antes de decidir si un skb no lineal no clonado puede omitir skb_cow_data(). Si la coalescencia de recepción TCP ha movido fragmentos compartidos a un skb sin marcar, ESP puede ver skb_has_shared_frag() como falso y descifrar in situ sobre fragmentos respaldados por la caché de páginas. Propagar SKBFL_SHARED_FRAG cuando skb_try_coalesce() transfiere fragmentos paginados. La ruta de copia del espacio de cola no necesita el marcador porque copia bytes en los datos lineales de @to en lugar de transferir descriptores de fragmentos.

Affected operating systems

  • linux

    amazon / amazon_linux

  • linux

    ubuntu / awsbionic

  • linux

    ubuntu / awsjammy

  • linux

    ubuntu / awsnoble

  • linux

    ubuntu / awsresolute

  • linux

    ubuntu / awsxenial

  • linux

    ubuntu / aws-6.8jammy

  • linux

    ubuntu / aws-hwexenial

  • linux

    ubuntu / azurejammy

  • linux

    ubuntu / azurenoble

  • linux

    ubuntu / azureresolute

  • linux

    ubuntu / azurexenial

  • linux

    ubuntu / azure-4.15bionic

  • linux

    suse / basesystem_module15

  • linux

    debian / debian_linux11.0

  • linux

    debian / debian_linux12.0

  • linux

    debian / debian_linux13.0

  • linux

    suse / development_tools_module15

  • linux

    redhat / enterprise_linux9.0

  • linux

    redhat / enterprise_linux10.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux_aus8.6

  • linux

    redhat / enterprise_linux_aus8.4

  • linux

    redhat / enterprise_linux_eus9.6

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • arista

    cloudvision_agni2024.4.0 – 2025.2.2

  • arista

    cloudvision_portal2024.2.0 – 2026.1.0

  • arista

    velocloud_edge4.5.0 – 6.4.1

  • arista

    velocloud_gateway

  • arista

    velocloud_orchestrator

  • IBM

    QRadar SIEM<7.5.0 UP15 IF06

  • redhat

    openshift_container_platform4.12 – 4.12.89

  • redhat

    openshift_container_platform4.13 – 4.13.66

  • redhat

    openshift_container_platform4.14 – 4.14.65

  • redhat

    openshift_container_platform4.15 – 4.15.64

  • redhat

    openshift_container_platform4.16 – 4.16.61

  • redhat

    openshift_container_platform4.17 – 4.17.53

  • redhat

    openshift_container_platform4.18 – 4.18.40

  • redhat

    openshift_container_platform4.19 – 4.19.30

  • redhat

    openshift_container_platform4.20 – 4.20.21

  • redhat

    openshift_container_platform4.21 – 4.21.14

  • redhat

    openshift_container_platform

  • siemens

    simatic_ax_runtime

  • suse

    caas_platform

  • suse

    enterprise_storage

  • suse

    manager_proxy

  • suse

    manager_retail_branch_server

  • suse

    manager_server

  • suse

    openstack_cloud

References & sources

Linked CVEs

Show 368 more CVEs

Linked advisories

IDCVE-2026-46300