| Title | Linuxカーネルにおける複数の脆弱性 |
|---|---|
| Summary | CERT/CCから本件に関するアドバイザリが公表されました。 <ul><li><a href='https://kb.cert.org/vuls/id/980487' target='_blank'>VU#980487: Local privilege escalation in Linux Kernel (Dirty Frag)</a></li><li><a href='https://kb.cert.org/vuls/id/260001' target='_blank'>VU#260001: Linux kernel contains local privilege escalation vulnerability (Copy Fail)</a></li></ul> |
| Possible impacts | 想定される影響は各脆弱性により異なりますが、次のような影響を受ける可能性があります。<ul><li>脆弱性を組み合わせることで、認証されたローカルのユーザによって、権限を昇格される(CVE-2026-43284、CVE-2026-43500)</li><li>認証されたローカルのユーザによって、権限を昇格される(CVE-2026-31431)</li></ul> |
| Solution | CERT/CCのアドバイザリを参照してください。 |
| Publication Date | May 25, 2026, midnight |
| Registration Date | May 26, 2026, 2:07 p.m. |
| Last Update | May 26, 2026, 2:07 p.m. |
| Linux |
| Linux Kernel |
| No | Changed Details | Date of change |
|---|---|---|
| 1 | [2026年05月26日] 掲載 |
May 26, 2026, 2:07 p.m. |
| Summary | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of There is no benefit in operating in-place in algif_aead since the |
|---|---|
| Publication Date | April 22, 2026, 6:16 p.m. |
| Registration Date | April 25, 2026, 4:04 a.m. |
| Last Update | April 27, 2026, 11:16 p.m. |
| Summary | In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP That leaves an ESP-in-UDP packet made from shared pipe pages looking Mark IPv4/IPv6 datagram splice frags with SKBFL_SHARED_FRAG, matching This intentionally does not change ESP output. In esp_output_head(), |
|---|---|
| Publication Date | May 8, 2026, 5:16 p.m. |
| Registration Date | May 9, 2026, 4:12 a.m. |
| Last Update | May 15, 2026, 2:16 a.m. |
| Configuration1 | or higher | or less | more than | less than | |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.11 | 5.10.255 | |||
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.12 | 5.15.205 | |||
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 | 6.1.171 | |||
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 | 6.6.138 | |||
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 | 6.12.87 | |||
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 | 6.18.28 | |||
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 7.0 | 7.0.5 | |||
| Summary | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present The DATA-packet handler in rxrpc_input_call_event() and the RESPONSE Extend the gate to also unshare when skb_has_frag_list() or |
|---|---|
| Publication Date | May 11, 2026, 5:16 p.m. |
| Registration Date | May 12, 2026, 4:13 a.m. |
| Last Update | May 18, 2026, 1:16 a.m. |
| Configuration1 | or higher | or less | more than | less than | |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.3 | 6.18.29 | |||
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 | 7.0.6 | |||
| cpe:2.3:o:linux:linux_kernel:5.3:-:*:*:*:*:*:* | |||||
| cpe:2.3:o:linux:linux_kernel:5.3:rc7:*:*:*:*:*:* | |||||
| cpe:2.3:o:linux:linux_kernel:5.3:rc8:*:*:*:*:*:* | |||||
| cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* | |||||
| cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* | |||||