Dirty Frag kernel CVEs (CVE-2026-43284 / CVE-2026-43500) - ESP/IPsec path - follow-up to the Copy Fa
Ally Member
Dear Zyxel team
There is already a helpful thread on the related Copy Fail vulnerability where a Zyxel employee confirmed the appliance is not practically exposed, since exploitation needs a local unprivileged user to run code and the firewall/AP do not offer that attack surface:
https://community.zyxel.com/en/discussion/32815/linux-expoit-cve-2026-31431
I would like to ask specifically about the related "Dirty Frag" disclosure, which that thread predates and does not cover:
- CVE-2026-43284 - xfrm/ESP IPsec input path (esp4, esp6 modules)
- CVE-2026-43500 - the RxRPC page-cache write half of the chain
These are Linux kernel local privilege escalation flaws affecting mainline kernels since 2017. What makes them more relevant to me than Copy Fail is the location: CVE-2026-43284 sits in the ESP/IPsec input path, not the crypto subsystem - directly in code that anyone running IPsec VPN on ZLD is exercising.
My questions (I run a USG FLEX 50W, originally branded USG20W-VPN, on firmware V5.42 ABAR.1):
- Is the vulnerable ESP code even present and reachable in ZLD's kernel?
- Does the same "no local shell, so not practically exploitable" reasoning from the Copy Fail thread apply equally to Dirty Frag, or does the IPsec processing path change the picture?
- If a fix is needed, what is the planned remediation and timeline?
One related point raised in the other thread that I would value a comment on: a web-service RCE could in principle chain past the "needs local access" precondition without the attacker touching the firewall directly. Does that scenario affect Zyxel's assessment here?
Thanks in advance.
Accepted Solution
-
Hi @Zyxel_USG_User ,
Regarding your inquiry about CVE-2026-43284 and CVE-2026-43500, we confirm that the Zyxel USG FLEX series is NOT AFFECTED by either vulnerability. No action, patch, or configuration change is required.
Zyxel_Judy
1
All Replies
-
Hi @Zyxel_USG_User ,
Regarding your inquiry about CVE-2026-43284 and CVE-2026-43500, we confirm that the Zyxel USG FLEX series is NOT AFFECTED by either vulnerability. No action, patch, or configuration change is required.
Zyxel_Judy
1 -
Thank you for the confirmation- much appreciated. Good to have a clear statement on record that the USG FLEX series is not affected by either CVE. Closing the thread on my side.
Best regards
0
Categories
- All Categories
- 442 Beta Program
- 3K Nebula
- 229 Nebula Ideas
- 130 Nebula Status and Incidents
- 6.6K Security
- 661 USG FLEX H Series
- 359 Security Ideas
- 1.8K Switch
- 86 Switch Ideas
- 1.4K Wireless
- 56 Wireless Ideas
- 7.1K Consumer Product
- 305 Service & License
- 497 News and Release
- 95 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 5K FAQ
- 34 Documents
- 89 About Community
- 110 Security Highlight
Zyxel Employee