DSA-2026-223: Security Update for Dell Enterprise Sonic Distribution Copy Fail (CVE-2026-31431) and Dirty Frag (CVE-2026-43284, CVE-2026-43500) 

Sommaire: Dell Enterprise Sonic Distribution mitigation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

Cet article s’applique à Cet article ne s’applique pas à Cet article n’est lié à aucun produit spécifique. Toutes les versions de produits ne sont pas identifiées dans cet article.

Impact

High

Autres renseignements

Customers who create users only via the CLI are not affected by these vulnerabilities as the non-privileged users do not have shell access.

Détails

Third-party Component CVEs More Information
Linux Kernel CVE-2026-31431, CVE-2026-43284, CVE-2026-43500 https://nvd.nist.gov/vuln/searchThis hyperlink is taking you to a website outside of Dell Technologies.

 

Dell Technologies recommande à tous ses clients de tenir compte à la fois du score de base CVSS et de tous les scores temporels et environnementaux pertinents qui pourraient avoir une incidence sur la gravité potentielle associée à une vulnérabilité de sécurité particulière.

Produits touchés et correction

Product Affected Versions Remediated Versions Link
Dell Enterprise SONiC Distribution Versions prior to 4.5.3 Version 4.5.3 Link to update

 

Product Affected Versions Remediated Versions Link
Dell Enterprise SONiC Distribution Versions prior to 4.5.3 Version 4.5.3 Link to update

 

The Affected Products and Remediation table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.

Solutions de contournement et mesures d’atténuation

CVE ID Workaround and Mitigation
CVE-2026-31431, CVE-2026-43284, CVE-2026-43500

For customers who configure general Linux shell access or want to implement defense-in-depth measures, we recommend adding an additional filter to block dynamic loading of the affected modules.

1) Disable Vulnerable Kernel Module Loading

From the Linux shell as system admin add the following filter to your system configuration:

#Restrict loading of the affected kernel modules

echo "install algif_aead /bin/false" | sudo tee /etc/modprobe.d/disable-algif.conf

echo "install esp4 /bin/false" | sudo tee /etc/modprobe.d/disable-esp4.conf

echo "install rxrpc /bin/false" | sudo tee /etc/modprobe.d/disable-rxrpc.conf

If OSPFv3 IPSec authentication is not in use, apply the additional filter below as well:

echo "install esp6 /bin/false" | sudo tee /etc/modprobe.d/disable-esp6.conf

After applying the configuration, update module preferences:

sudo depmod -a

2) Verification

To verify the module is blocked:

#Check if any of the modules are active

lsmod | grep -E 'algif_aead|rxrpc|esp4|esp6'

#If necessary, unload the module if it is currently loaded

sudo modprobe -r <module_name>

#Attempt to load each module (should fail)

sudo modprobe algif_aead

#Expected output: modprobe: ERROR: ../libkmod/libkmod-module.c:1047 command_do() Error running install command '/bin/false' for module algif_aead: retcode 1

Persistence

The configuration will persist across system reboots. No additional steps are required.

 

Historique de révision

RevisionDateDescription
1.02026-05-15Initial Release
2.02026-05-15Formatting changes only.  No changes to content.  
3.02026-06-10Link provided for the 4.5.3 release

 

Renseignements connexes

Produits touchés

Enterprise SONiC Distribution, PowerSwitch E3200-ON Series, PowerSwitch S3248T-ON, PowerSwitch S4348F/S4348T-ON, PowerSwitch S5212F-ON, PowerSwitch S5224F-ON, PowerSwitch S5232F-ON, PowerSwitch S5248F-ON, PowerSwitch S5296F-ON, PowerSwitch S5448F-ON , PowerSwitch Z9264F-ON, PowerSwitch Z9332F-ON, PowerSwitch Z9432F-ON, PowerSwitch Z9664F-ON, PowerSwitch Z9864F-ON ...
Propriétés de l’article
Numéro d’article: 000465379
Type d’article: Dell Security Advisory
Dernière modification: 10 juin 2026
Obtenez des réponses à vos questions auprès d’autre utilisateurs de Dell
Services de soutien
Vérifiez si votre appareil est couvert par les services de soutien.