# Check Point Response to CVE-2026-31431 (Copy Fail), CVE-2026-43284, CVE-2026-43500 (Dirty Frag) and CVE-2026-46300 (Fragnesia)

Please read this important update from Check Point.

**Security Alert:**

Low  
**Product**: Security Gateways, Security Management  
**Version**: R82, R82.10  
**Last Modified**: 2026-05-18

## Symptoms

- On April 22, 2026, CERT published vulnerabilities in the Linux kernel.

This issue received the ID [CVE-2026-31431](https://www.cve.org/CVERecord?id=CVE-2026-31431).

It addresses an issue in the Linux kernel’s cryptographic interface ( _algif_aead_).

- On May 7, 2026, a second related vulnerability was published, known as [CVE-2026-43284](https://www.cve.org/CVERecord?id=CVE-2026-43284), addressing an issue in the Linux kernel's IPsec/ESP subsystem ( _esp4/esp6_).

- On May 11, 2026, a third related vulnerability was disclosed, known as [CVE-2026-43500](https://www.cve.org/CVERecord?id=CVE-2026-43500), addressing an issue in the Linux kernel's RxRPC networking subsystem ( _rxrpc_).

These two vulnerabilities are collectively known as "Dirty Frag" and belong to the same vulnerability class as "Copy Fail".

- On May 13, 2026, a fourth related vulnerability was disclosed: an issue in the Linux kernel's XFRM ESP-in-TCP subsystem (esp4/esp6 via the espintcp path / skb_try_coalesce).

This issue received the ID [CVE-2026-46300](https://www.cve.org/CVERecord?id=CVE-2026-46300) (Fragnesia).

CVE-2026-43284 and CVE-2026-43500 are collectively known as Dirty Frag. CVE-2026-46300 (Fragnesia) is a separate but related flaw in the same code area.

## Solution

**Practical risk: Low.** These vulnerabilities require non-root local code execution, which the Gaia OS standard role model does not expose, because administrative access goes through Expert mode (already root), and non-admin roles are restricted to Clish.

If you have created non-admin users with non-Clish shell access (treating them as effectively administrative), and this was not intentional, remove the shell access.

By default, only _adminRole_ users have shell access; all other roles use Clish.

Note:

- R81.20 and earlier versions are not affected.
- CVE-2026-43500 does not affect R82 (only R82.10 and higher).

## Article Properties

**Access Level**: General  
**Severity**: Low  
**Status**: Approved  
**Date Created**: 2026-05-04  
**Last Modified**: 2026-05-18
