← Back to blog

Critical Linux Kernel Flaws Expose Systems to Privilege Escalation and Remote Attacks

Multiple high-severity vulnerabilities including CVE-2026-43503 and CVE-2025-27558 affect core Linux subsystems, risking privilege escalation and packet injection.

TL;DR

  • A critical flaw in XFRM ESP-in-TCP (Fragnesia - CVE-2026-43503) allows local attackers to escalate privileges or escape containers.
  • WiFi vulnerability CVE-2025-27558 enables physically proximate attackers to inject packets via improper mesh frame handling.
  • Dozens of additional flaws across networking, file systems, and drivers increase risk of system compromise.
  • Affects multiple Ubuntu kernel variants including NVIDIA Tegra, Oracle, OEM, and HWE editions.
  • Immediate patching recommended; updates address flaws in TCP, Netfilter, IPv4/IPv6, and more.

Recent Ubuntu security advisories highlight a series of critical vulnerabilities in the Linux kernel that could allow attackers to escalate privileges, escape containers, or remotely compromise systems. Among the most significant is CVE-2026-43503, known as 'Fragnesia,' which affects the XFRM ESP-in-TCP subsystem and poses a serious risk to containerized environments.

In addition, CVE-2025-27558 targets the WiFi stack's mesh networking implementation, allowing physically nearby attackers to inject malicious packets. These flaws, along with dozens of others spanning core kernel subsystems, underscore the importance of immediate patching across all affected platforms.

Privilege Escalation and Container Escape Risks

  • The Fragnesia vulnerability (CVE-2026-43503) resides in the XFRM ESP-in-TCP subsystem and can lead to privilege escalation or container escape.
  • Another related flaw, Dirty Frag (CVE-2026-43284), involves improper handling of shared page fragments during socket operations.
  • These issues affect local attackers but carry high impact due to potential system-level access.
  • Both flaws are present in multiple kernel variants including HWE and standard distributions.

Networking and Remote Attack Vectors

  • CVE-2025-27558 impacts WiFi mesh networks due to improper aggregated frame handling, allowing packet injection by physically proximate attackers.
  • Flaws span widely used protocols such as TCP, SCTP, IPv4, IPv6, Multipath TCP, and RxRPC.
  • Netfilter, network traffic control, and various drivers (InfiniBand, NVME, Thunderbolt) also contain exploitable bugs.
  • Many of these vulnerabilities could be chained for remote exploitation depending on system configuration.

Affected Subsystems and Widespread Impact

  • File systems including Ext4 and NFS are impacted, alongside critical infrastructure like locking primitives and tracing tools.
  • GPU, media, and vendor-specific drivers (e.g., NVIDIA Tegra, STMicroelectronics) introduce additional exposure points.
  • Multiple Ubuntu kernel editions are affected: generic, HWE, OEM, Oracle, and specialized builds like NVIDIA Tegra IGX.
  • Over 40 CVEs are addressed across the consolidated advisories, indicating broad kernel surface area compromise.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.