It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503)
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems:
4.15.0-253.2654.15.0-1204.2194.15.0-1187.2044.15.0-1176.1814.15.0-1156.1674.15.0-2112.1184.15.0-1149.1614.15.0-2095.101