CVE-2026-46300
In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() can attach paged frags from @from to @to. If @from has SKBFL_SHARED_FRAG set, the resulting @to skb can contain the same externally-owned or page-cache-backed frags, but the shared-frag marker is currently lost. That breaks the invariant relied on by later in-place writers. In particular, ESP input checks skb_has_shared_frag() before deciding whether an uncloned nonlinear skb can skip skb_cow_data(). If TCP receive coalescing has moved shared frags into an unmarked skb, ESP can see skb_has_shared_frag() as false and decrypt in place over page-cache backed frags. Propagate SKBFL_SHARED_FRAG when skb_try_coalesce() transfers paged frags. The tailroom copy path does not need the marker because it copies bytes into @to's linear data rather than transferring frag descriptors.
- Published May 23, 2026
- CVSS 7.8 high
- 2.4% chance of exploitation in the next 30 days (EPSS)
- A Metasploit module exploits it
- A fix is available
Affected software
In the news
- Exploits and vulnerabilities in Q2 2026 Securelist ·
- Copy Fail and Its Descendants: A Real Human's Guide to Kernel Page-Cache LPEs VulnCheck Blog ·
- Ongoing updates on Copy.fail and variants AWS Security Bulletins ·
- Fragnesia Local Privilege Escalation report via ESP-in-TCP in the Linux Kernel AWS Security Bulletins ·
- Dirty Frag and other issues in Amazon Linux kernels AWS Security Bulletins ·
- Networking subsystem Privilege Escalation - Linux Kernel - "Dirty Frag" Red Hat Security Bulletins ·
- CVE-2026-31431 AWS Security Bulletins ·