sk184928 - Check Point Response to CVE-2026-31431 (Copy Fail), CVE-2026-43284, CVE-2026-43500 (Dirty Frag) and CVE-2026-46300 (Fragnesia)
Check Point Response to CVE-2026-31431 (Copy Fail), CVE-2026-43284, CVE-2026-43500 (Dirty Frag) and CVE-2026-46300 (Fragnesia)
Please read this important update from Check Point.
Security Alert:
Low
Product: Security Gateways, Security Management
Version: R82, R82.10
Last Modified: 2026-05-18
Symptoms
- On April 22, 2026, CERT published vulnerabilities in the Linux kernel.
This issue received the ID CVE-2026-31431.
It addresses an issue in the Linux kernel’s cryptographic interface ( algif_aead).
On May 7, 2026, a second related vulnerability was published, known as CVE-2026-43284, addressing an issue in the Linux kernel's IPsec/ESP subsystem ( esp4/esp6).
On May 11, 2026, a third related vulnerability was disclosed, known as CVE-2026-43500, addressing an issue in the Linux kernel's RxRPC networking subsystem ( rxrpc).
These two vulnerabilities are collectively known as "Dirty Frag" and belong to the same vulnerability class as "Copy Fail".
- On May 13, 2026, a fourth related vulnerability was disclosed: an issue in the Linux kernel's XFRM ESP-in-TCP subsystem (esp4/esp6 via the espintcp path / skb_try_coalesce).
This issue received the ID CVE-2026-46300 (Fragnesia).
CVE-2026-43284 and CVE-2026-43500 are collectively known as Dirty Frag. CVE-2026-46300 (Fragnesia) is a separate but related flaw in the same code area.
Solution
Practical risk: Low. These vulnerabilities require non-root local code execution, which the Gaia OS standard role model does not expose, because administrative access goes through Expert mode (already root), and non-admin roles are restricted to Clish.
If you have created non-admin users with non-Clish shell access (treating them as effectively administrative), and this was not intentional, remove the shell access.
By default, only adminRole users have shell access; all other roles use Clish.
Note:
- R81.20 and earlier versions are not affected.
- CVE-2026-43500 does not affect R82 (only R82.10 and higher).
Article Properties
Access Level: General
Severity: Low
Status: Approved
Date Created: 2026-05-04
Last Modified: 2026-05-18