> Source: [sk184928](https://support.checkpoint.com/results/sk/sk184928)

# sk184928 - Check Point Response to CVE-2026-31431 (Copy Fail), CVE-2026-43284, CVE-2026-43500 (Dirty Frag) and CVE-2026-46300 (Fragnesia)

| Property | Value |
|----------|-------|
| Solution ID | sk184928 |
| Date Created | 2026-05-04 |
| Last Modified | 2026-05-18 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server |
| Versions | R82.10, R82, R82.10, R82 |

## Symptoms

- * On April 22, 2026, CERT published vulnerabilities in the Linux kernel.   
  This issue received the ID [CVE-2026-31431](https://www.cve.org/CVERecord?id=CVE-2026-31431).   
  It addresses an issue in the Linux kernel's cryptographic interface (*algif_aead*).

* On May 7, 2026, a second related vulnerability was published, known as [CVE-2026-43284](https://www.cve.org/CVERecord?id=CVE-2026-43284), addressing an issue in the Linux kernel's IPsec/ESP subsystem (*esp4/esp6* ).  

  On May 11, 2026, a third related vulnerability was disclosed, known as [CVE-2026-43500](https://www.cve.org/CVERecord?id=CVE-2026-43500), addressing an issue in the Linux kernel's RxRPC networking subsystem (*rxrpc* ).  

  These two vulnerabilities are collectively known as "Dirty Frag" and belong to the same vulnerability class as "Copy Fail".
* <br />

  On May 13, 2026, a fourth related vulnerability was disclosed: an issue in the Linux kernel's XFRM ESP-in-TCP subsystem (esp4/esp6 via the espintcp path / skb_try_coalesce).  
  This issue received the ID [CVE-2026-46300](https://www.cve.org/CVERecord?id=CVE-2026-46300) (Fragnesia).  

  CVE-2026-43284 and CVE-2026-43500 are collectively known as Dirty Frag. CVE-2026-46300 (Fragnesia) is a separate but related flaw in the same code area.

  <br />

## Solution

**Practical risk: Low.** These vulnerabilities require non-root local code execution, which the Gaia OS standard role model does not expose, because administrative access goes through Expert mode (already root), and non-admin roles are restricted to Clish.
If you have created non-admin users with non-Clish shell access (treating them as effectively administrative), and this was not intentional, remove the shell access.   
By default, only *adminRole* users have shell access; all other roles use Clish.  

Note:   

* R81.20 and earlier versions are not affected.
* CVE-2026-43500 does not affect R82 (only R82.10 and higher).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
