sk184928 - Check Point Response to CVE-2026-31431 (Copy Fail), CVE-2026-43284, CVE-2026-43500 (Dirty Frag) and CVE-2026-46300 (Fragnesia)

Check Point Response to CVE-2026-31431 (Copy Fail), CVE-2026-43284, CVE-2026-43500 (Dirty Frag) and CVE-2026-46300 (Fragnesia)

Please read this important update from Check Point.

Security Alert:

Low
Product: Security Gateways, Security Management
Version: R82, R82.10
Last Modified: 2026-05-18

Symptoms

This issue received the ID CVE-2026-31431.

It addresses an issue in the Linux kernel’s cryptographic interface ( algif_aead).

These two vulnerabilities are collectively known as "Dirty Frag" and belong to the same vulnerability class as "Copy Fail".

This issue received the ID CVE-2026-46300 (Fragnesia).

CVE-2026-43284 and CVE-2026-43500 are collectively known as Dirty Frag. CVE-2026-46300 (Fragnesia) is a separate but related flaw in the same code area.

Solution

Practical risk: Low. These vulnerabilities require non-root local code execution, which the Gaia OS standard role model does not expose, because administrative access goes through Expert mode (already root), and non-admin roles are restricted to Clish.

If you have created non-admin users with non-Clish shell access (treating them as effectively administrative), and this was not intentional, remove the shell access.

By default, only adminRole users have shell access; all other roles use Clish.

Note:

Article Properties

Access Level: General
Severity: Low
Status: Approved
Date Created: 2026-05-04
Last Modified: 2026-05-18