DSA-2026-223: Security Update for Dell Enterprise Sonic Distribution Copy Fail (CVE-2026-31431) and Dirty Frag (CVE-2026-43284, CVE-2026-43500) 

Zusammenfassung: Dell Enterprise Sonic Distribution mitigation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

Dieser Artikel gilt für Dieser Artikel gilt nicht für Dieser Artikel ist nicht an ein bestimmtes Produkt gebunden. In diesem Artikel werden nicht alle Produktversionen aufgeführt.

Auswirkungen

High

Weitere Angaben

Customers who create users only via the CLI are not affected by these vulnerabilities as the non-privileged users do not have shell access.

Details

Third-party Component CVEs More Information
Linux Kernel CVE-2026-31431, CVE-2026-43284, CVE-2026-43500 https://nvd.nist.gov/vuln/searchThis hyperlink is taking you to a website outside of Dell Technologies.

 

Dell Technologies empfiehlt allen Kunden, sowohl die CVSS-Gesamtbewertung als auch alle relevanten zeitlichen und umweltbezogenen Bewertungen zu berücksichtigen, die sich auf den potenziellen Schweregrad einer bestimmten Sicherheitsschwachstelle auswirken können.

Betroffene Produkte und Korrektur

Product Affected Versions Remediated Versions Link
Dell Enterprise SONiC Distribution Versions prior to 4.5.3 Version 4.5.3 Link to update

 

Product Affected Versions Remediated Versions Link
Dell Enterprise SONiC Distribution Versions prior to 4.5.3 Version 4.5.3 Link to update

 

The Affected Products and Remediation table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.

Workarounds und Korrekturmaßnahmen

CVE ID Workaround and Mitigation
CVE-2026-31431, CVE-2026-43284, CVE-2026-43500

For customers who configure general Linux shell access or want to implement defense-in-depth measures, we recommend adding an additional filter to block dynamic loading of the affected modules.

1) Disable Vulnerable Kernel Module Loading

From the Linux shell as system admin add the following filter to your system configuration:

#Restrict loading of the affected kernel modules

echo "install algif_aead /bin/false" | sudo tee /etc/modprobe.d/disable-algif.conf

echo "install esp4 /bin/false" | sudo tee /etc/modprobe.d/disable-esp4.conf

echo "install rxrpc /bin/false" | sudo tee /etc/modprobe.d/disable-rxrpc.conf

If OSPFv3 IPSec authentication is not in use, apply the additional filter below as well:

echo "install esp6 /bin/false" | sudo tee /etc/modprobe.d/disable-esp6.conf

After applying the configuration, update module preferences:

sudo depmod -a

2) Verification

To verify the module is blocked:

#Check if any of the modules are active

lsmod | grep -E 'algif_aead|rxrpc|esp4|esp6'

#If necessary, unload the module if it is currently loaded

sudo modprobe -r <module_name>

#Attempt to load each module (should fail)

sudo modprobe algif_aead

#Expected output: modprobe: ERROR: ../libkmod/libkmod-module.c:1047 command_do() Error running install command '/bin/false' for module algif_aead: retcode 1

Persistence

The configuration will persist across system reboots. No additional steps are required.

 

Revisionsverlauf

RevisionDateDescription
1.02026-05-15Initial Release
2.02026-05-15Formatting changes only.  No changes to content.  
3.02026-06-10Link provided for the 4.5.3 release

 

Zugehörige Informationen

Betroffene Produkte

Enterprise SONiC Distribution, PowerSwitch E3200-ON Series, PowerSwitch S3248T-ON, PowerSwitch S4348F/S4348T-ON, PowerSwitch S5212F-ON, PowerSwitch S5224F-ON, PowerSwitch S5232F-ON, PowerSwitch S5248F-ON, PowerSwitch S5296F-ON, PowerSwitch S5448F-ON , PowerSwitch Z9264F-ON, PowerSwitch Z9332F-ON, PowerSwitch Z9432F-ON, PowerSwitch Z9664F-ON, PowerSwitch Z9864F-ON ...
Artikeleigenschaften
Artikelnummer: 000465379
Artikeltyp: Dell Security Advisory
Zuletzt geändert: 10 Juni 2026
Antworten auf Ihre Fragen erhalten Sie von anderen Dell NutzerInnen
Support Services
Prüfen Sie, ob Ihr Gerät durch Support Services abgedeckt ist.