ChangeLog for: 2026-05-08 23:14:25
a/kernel-generic-6.18.28-x86_64-1.txz: Upgraded.
This update fixes a critical security issue:
xfrm: esp: avoid in-place decrypt on shared skb frags.
This update addresses a Linux kernel local privilege escalation attack known
as "Dirty Frag." Please note that there's a second CVE (CVE-2026-43500) that
is not yet patched upstream.
Mitigation: If for some reason it's not possible to upgrade the kernel right
away you may blacklist or remove the kernel modules esp4.ko and esp6.ko
(CVE-2026-43284) and rxrpc.ko (CVE-2026-43500).
Also remove the modules from the kernel if they have been loaded:
rmmod esp4 esp6 rxrpc
And, drop the file caches in case in-memory program copies have already
been compromised. Make sure possibly affected programs do not have any
open sessions first:
sh -c "echo 3 > /proc/sys/vm/drop_caches"
For more information, see:
https://github.com/V4bel/dirtyfrag
https://www.cve.org/CVERecord?id=CVE-2026-43284
(* Security fix *)
d/google-go-lang-1.26.3-x86_64-1.txz: Upgraded.
d/kernel-headers-6.18.28-x86-1.txz: Upgraded.
k/kernel-source-6.18.28-noarch-1.txz: Upgraded.
l/pycurl-7.46.0-x86_64-1.txz: Upgraded.
l/python-trove-classifiers-2026.5.7.17-x86_64-1.txz: Upgraded.
n/fetchmail-6.6.4-x86_64-1.txz: Upgraded.
xap/mozilla-thunderbird-140.10.2esr-x86_64-1.txz: Upgraded.
y/nethack-5.0.0-x86_64-4.txz: Rebuilt.
Another fix for the HACK= sed substitution. Should be good now! :-)
Thanks to zapwai.
isolinux/initrd.img: Rebuilt.
kernels/*: Upgraded.
testing/packages/linux-7.0.x/kernel-generic-7.0.5-x86_64-1.txz: Upgraded.
This update fixes a critical security issue:
xfrm: esp: avoid in-place decrypt on shared skb frags.
This update addresses a Linux kernel local privilege escalation attack known
as "Dirty Frag." Please note that there's a second CVE (CVE-2026-43500) that
is not yet patched upstream.
Mitigation: If for some reason it's not possible to upgrade the kernel right
away you may blacklist or remove the kernel modules esp4.ko and esp6.ko
(CVE-2026-43284) and rxrpc.ko (CVE-2026-43500).
Also remove the modules from the kernel if they have been loaded:
rmmod esp4 esp6 rxrpc
And, drop the file caches in case in-memory program copies have already
been compromised. Make sure possibly affected programs do not have any
open sessions first:
sh -c "echo 3 > /proc/sys/vm/drop_caches"
For more information, see:
https://github.com/V4bel/dirtyfrag
https://www.cve.org/CVERecord?id=CVE-2026-43284
(* Security fix *)
testing/packages/linux-7.0.x/kernel-headers-7.0.5-x86-1.txz: Upgraded.
testing/packages/linux-7.0.x/kernel-source-7.0.5-noarch-1.txz: Upgraded.
usb-and-pxe-installers/usbboot.img: Rebuilt.