Ubuntu Security Notices USN-8390-1 USN-8390-1: Linux kernel vulnerability Publication date 4 June 2026 Overview The system could be made to run programs as an administrator. Releases 18.04 LTS 14.04 LTS Open side navigation Close side navigation Packages Details Update instructions References Related notices Packages linux - Linux kernel linux-azure - Linux kernel for Microsoft Azure Cloud systems linux-azure-4.15 - Linux kernel for Microsoft Azure Cloud systems linux-azure-fips - Linux kernel for Microsoft Azure Cloud systems with FIPS linux-fips - Linux kernel with FIPS linux-gcp-4.15 - Linux kernel for Google Cloud Platform (GCP) systems linux-gcp-fips - Linux kernel for Google Cloud Platform (GCP) systems with FIPS linux-kvm - Linux kernel for cloud environments linux-oracle - Linux kernel for Oracle Cloud systems Details It was discovered that the Linux kernel did not properly handle shared page fragments during socket buffer operations, collectively known as Dirty Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the RxRPC networking subsystem when processing paged fragments. A local attacker could use this to escalate privileges, or possibly escape a container. It was discovered that the Linux kernel did not properly handle shared page fragments during socket buffer operations, collectively known as Dirty Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the RxRPC networking subsystem when processing paged fragments. A local attacker could use this to escalate privileges, or possibly escape a container. Update instructions After a standard system update you need to reboot your computer to make all the necessary changes. Learn more about how to get the fixes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. The problem can be corrected by updating your system to the following package versions: Ubuntu Release Package Version 18.04 LTS bionic linux-image-4.15.0-1148-fips – 4.15.0-1148.160 FIPS Updates FIPS-140 certified package with security fixes. Available with Ubuntu Pro. linux-image-4.15.0-1155-oracle – 4.15.0-1155.166 Ubuntu Pro Fix available with Ubuntu Pro . linux-image-4.15.0-1175-kvm – 4.15.0-1175.180 Ubuntu Pro Fix available with Ubuntu Pro . linux-image-4.15.0-1186-gcp – 4.15.0-1186.203 Ubuntu Pro Fix available with Ubuntu Pro . linux-image-4.15.0-1202-azure – 4.15.0-1202.217 Ubuntu Pro Fix available with Ubuntu Pro . linux-image-4.15.0-2094-gcp-fips – 4.15.0-2094.100 FIPS Updates FIPS-140 certified package with security fixes. Available with Ubuntu Pro. linux-image-4.15.0-2111-azure-fips – 4.15.0-2111.117 FIPS Updates FIPS-140 certified package with security fixes. Available with Ubuntu Pro. linux-image-4.15.0-251-generic – 4.15.0-251.263 Ubuntu Pro Fix available with Ubuntu Pro . linux-image-4.15.0-251-lowlatency – 4.15.0-251.263 Ubuntu Pro Fix available with Ubuntu Pro . linux-image-azure-4.15 – 4.15.0.1202.170 Ubuntu Pro Fix available with Ubuntu Pro . linux-image-azure-fips – 4.15.0.2111.107 FIPS Updates FIPS-140 certified package with security fixes. Available with Ubuntu Pro. linux-image-azure-fips-4.15 – 4.15.0.2111.107 FIPS Updates FIPS-140 certified package with security fixes. Available with Ubuntu Pro. linux-image-azure-lts-18.04 – 4.15.0.1202.170 Ubuntu Pro Fix available with Ubuntu Pro . linux-image-fips – 4.15.0.1148.145 FIPS Updates FIPS-140 certified package with security fixes. Available with Ubuntu Pro. linux-image-gcp-4.15 – 4.15.0.1186.199 Ubuntu Pro Fix available with Ubuntu Pro . linux-image-gcp-fips – 4.15.0.2094.92 FIPS Updates FIPS-140 certified package with security fixes. Available with Ubuntu Pro. linux-image-gcp-fips-4.15 – 4.15.0.2094.92 FIPS Updates FIPS-140 certified package with security fixes. Available with Ubuntu Pro. linux-image-gcp-lts-18.04 – 4.15.0.1186.199 Ubuntu Pro Fix available with Ubuntu Pro . linux-image-generic – 4.15.0.251.235 Ubuntu Pro Fix available with Ubuntu Pro . linux-image-kvm – 4.15.0.1175.166 Ubuntu Pro Fix available with Ubuntu Pro . linux-image-lowlatency – 4.15.0.251.235 Ubuntu Pro Fix available with Ubuntu Pro . linux-image-oracle-4.15 – 4.15.0.1155.160 Ubuntu Pro Fix available with Ubuntu Pro . linux-image-oracle-lts-18.04 – 4.15.0.1155.160 Ubuntu Pro Fix available with Ubuntu Pro . linux-image-virtual – 4.15.0.251.235 Ubuntu Pro Fix available with Ubuntu Pro . 14.04 LTS trusty linux-image-4.15.0-1202-azure – 4.15.0-1202.217~14.04.1 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. linux-image-azure – 4.15.0.1202.217~14.04.1 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines. Get Ubuntu Pro References CVE-2026-43284 CVE-2026-43284 Related notices USN-8393-1 USN-8392-1 USN-8391-1 USN-8389-1 USN-8388-1 USN-8374-1 USN-8373-1 USN-8371-1 USN-8370-1 USN-8393-1 USN-8392-1 USN-8391-1 USN-8389-1 USN-8388-1 USN-8374-1 USN-8373-1 USN-8371-1 USN-8370-1 Have additional questions? Talk to a member of the team ›
A logic flaw in the Linux kernel's handling of shared page fragments ("Dirty Frag") within the XFRM ESP-in-TCP and RxRPC subsystems (CVE-2026-43284, CVSS 8.8 HIGH) allows a local attacker to escalate privileges or escape a container. The vulnerability affects kernel versions from 4.11 through 5.10.254, 5.12 through 5.15.204, 5.16 through 6.1.170, 6.2 through 6.6.137, and 6.7 through 6.12.86. The fix requires updating to specific patched kernel versions (e.g., 5.10.255, 5.15.205, 6.1.171, 6.6.138, 6.12.87, 6.18.28, or 7.0.5) and a system reboot, noting that third-party kernel modules must be recompiled due to an ABI change.