Alerts This Week
Warning Icon 1 566
Alerts This Week
Warning Icon 1 566

Fedora 43 Kernel Update 2026-abc00fb4e8 Fixes Dirtyfrag Important Exploit

fedora
Calendar Grey May 8, 2026
Dist Fedora Esm H88
Fedora 43 kernel update addresses the dirtyfrag issue with important fixes enhancing system security.
The 7.0.4 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree

Summary

The kernel meta package

Update Information:

The 7.0.4 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree. It also contains a fix for the dirtyfrag vulnerability. This covers CVE-2026-43284 and CVE-2026-43500. For users who experience a problem with the 7.0.4 rebase, a build of 6.19.14 with just the dirtyfrag fixes should be available in koji shortly.

Change Log

* Thu May 7 2026 Justin M. Forbes [7.0.4-100] - xfrm: esp: avoid in-place decrypt on shared skb frags (Kuan-Ting Chen) - rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present (Hyunwoo Kim) * Thu May 7 2026 Justin M. Forbes [7.0.4-0] - wifi: mt76: mt7925: fix incorrect TLV length in CLC command (Quan Zhou) - ASoC: SOF: Don't allow pointer operations on unconfigured streams (Mark Brown) - Turn on DVB_PT3 for Fedora at user request (Justin M. Forbes) - Enable MEDIA_TUNER_MXL301RF for Fedora (Justin M. Forbes) - mfd: bcm2835-pm: Add BCM2712 PM device support (Phil Elwell) - mfd: bcm2835-pm: Introduce SoC-specific type identifier (Phil Elwell) - Linux v7.0.4 * Thu Apr 30 2026 Justin M. Forbes [7.0.3-0] - Linux v7.0.3 * Mon Apr 27 2026 Justin M. Forbes [7.0.2-0] - drm/v3d: Reject empty multisync extension to prevent infinite loop (Ashutosh Desai) - net: macb: Use napi_schedule_irqoff() in IRQ handler (Kevin Hao) - net: macb: Use netif_napi_add_tx() instead of netif_napi_add() for TX NAPI (Kevin Hao) - net: macb: Remove dedicated IRQ handler for WoL (Kevin Hao) - net: macb: Factor out the handling of non-hot IRQ events into a separate function (Kevin Hao) - net: macb: Introduce macb_queue_isr_clear() helper function (Kevin Hao) - net: macb: Replace open-coded implementation with napi_schedule() (Kevin Hao) - net: macb: fix use of at91_default_usrio without CONFIG_OF (Conor Dooley) - net: macb: drop usrio pointer on EyeQ5 config (Tho Lebrun) - net: macb: set MACB_CAPS_USRIO_DISABLED if no usrio config is provided (Tho Lebrun) - net: macb: runtime detect MACB_CAPS_USRIO_DISABLED (Tho Lebrun) - net: macb: timer adjust mode is not supported (Conor Dooley) - net: macb: clean up tsu clk rate acquisition (Conor Dooley) - net: macb: warn on pclk use as a tsu_clk fallback (Conor Dooley) - net: macb: add mpfs specific usrio configuration (Conor Dooley) - net: macb: np4 doesn't need a usrio pointer (Conor Dooley) - net: macb: rework usrio refclk selection code (Conor Dooley) - net: macb: split USRIO_HAS_CLKEN capability in two (Conor Dooley) - net: macb: rename macb_default_usrio to at91_default_usrio as not all platforms have mii mode control in usrio (Conor Dooley) - Revert "net: macb: Clean up the .usrio settings in macb_config instances" (Conor Dooley) - net: macb: add support for Microchip pic64hpsc ethernet endpoint (Charles Perry) - net: macb: add safeguards for jumbo frame larger than 10240 (Charles Perry) - net: macb: set default_an_inband to true for SGMII (Charles Perry) - net: macb: Clean up the .usrio settings in macb_config instances (Kevin Hao) - net: macb: Clean up the .init settings in macb_config instances (Kevin Hao) - net: macb: Clean up the .clk_init setting in the macb_config instances (Kevin Hao) - net: cadence: macb: enable EEE for Mobileye EyeQ5 (Nicolai Buchwitz) - net: cadence: macb: enable EEE for Raspberry Pi RP1 (Nicolai Buchwitz) - net: cadence: macb: add ethtool EEE support (Nicolai Buchwitz) - net: cadence: macb: implement EEE TX LPI support (Nicolai Buchwitz) - net: cadence: macb: add EEE LPI statistics counters (Nicolai Buchwitz) - net: macb: use ethtool_sprintf to fill ethtool stats strings (Sean Chang) - net: macb: add the .pcs_inband_caps() callback for SGMII (Charles Perry) - net: macb: add support for reporting SGMII inband link status (Charles Perry) - net: macb: fix SGMII with inband aneg disabled (Charles Perry) - net: cadence: macb: add ethtool nway_reset support (Nicolai Buchwitz) - ARM: dts: broadcom: bcm2835-rpi: Move non simple-bus nodes to root level (Rob Herring (Arm)) - arm64: dts: broadcom: bcm2712: Move non simple-bus nodes to root level (Rob Herring (Arm)) - arm64: dts: broadcom: bcm2712-d-rpi-5-b: update uart10 interrupt (Gregor Herburger) - arm64: dts: broadcom: bcm2712-d-rpi-5-b: add fixes for pinctrl/pinctrl_aon (Gregor Herburger) - arm64: dts: broadcom: bcm2712-rpi-5-b: add pinctrl properties for csi i2cs (Gregor Herburger) - arm64: dts: broadcom: bcm2712: add camera backend node pispbe (Gregor Herburger) - arm64: dts: broadcom: rp1: add csi nodes (Gregor Herburger) - arm64: dts: broadcom: rp1: add i2c controller (Gregor Herburger) - arm64: dts: broadcom: bcm2712: Add V3D device node (Mara Canal) - arm64: dts: freescale: imx93: Add Ethos-U65 NPU and SRAM nodes (Rob Herring (Arm)) - redhat: configs: fedora: Enable AMD ISP4 MIPI camera solution (Kate Hsuan) - Documentation: add documentation of AMD isp 4 driver (Bin Du) - media: platform: amd: isp4 debug fs logging and more descriptive errors (Bin Du) - media: platform: amd: isp4 video node and buffers handling added (Bin Du) - media: platform: amd: isp4 subdev and firmware loading handling added (Bin Du) - media: platform: amd: Add isp4 fw and hw interface (Bin Du) - media: platform: amd: low level support for isp4 firmware (Bin Du) - media: platform: amd: Introduce amd isp4 capture driver (Bin Du) - Linux v7.0.2

References


[ 1 ] Bug #2467807 - [Major Incident] kernel: "Dirty Frag" is a new universal Local Privilege Escalation (LPE) vulnerability in the Linux kernel [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2467807

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-abc00fb4e8' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: kernel
Product: Fedora 43
Version: 7.0.4
Release: 100.fc43
Summary: The Linux kernel

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here