◆ FORTINET ◆ Security Advisory

Published Date: June 3, 2026

CVE: CVE-2026-43284

Advisory Summary

⚠️ Critical Linux Kernel Vulnerability: Dirty Frag (CVSS 7.9)

Fortinet has disclosed a significant security vulnerability impacting the Linux kernel, designated as Dirty Frag, arising from the chaining of two vulnerabilities: CVE-2026-43284 and CVE-2026-43500. This vulnerability affects the way kernel networking handles fragmented socket buffers (skbs) associated with encrypted packet processing and memory page sharing.

Impact:
This vulnerability holds a CVSSv3 score of 7.9, implying a high severity risk for Linux-based infrastructure, particularly in environments running kernel versions prior to these patches. Data centers, cloud providers, and any enterprise-grade Linux deployments that utilize ESP or rxrpc-based networking stacks should prioritize applying these kernel updates immediately to mitigate exploitation risk. Failure to patch could allow attackers to manipulate encrypted network traffic or leak sensitive data from shared memory pages.

Fortinet’s advisory helps IT security and infrastructure teams strengthen Linux-based assets, guarding against sophisticated memory handling vulnerabilities in critical network subsystems.

🔗

Reference: Vendor Advisory