DSA-2026-223: Security Update for Dell Enterprise Sonic Distribution Copy Fail (CVE-2026-31431) and Dirty Frag (CVE-2026-43284, CVE-2026-43500) 

Résumé: Dell Enterprise Sonic Distribution mitigation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

Cet article concerne Cet article ne concerne pas Cet article n’est associé à aucun produit spécifique. Toutes les versions du produit ne sont pas identifiées dans cet article.

Impact

High

Détails supplémentaires

Customers who create users only via the CLI are not affected by these vulnerabilities as the non-privileged users do not have shell access.

Détails

Third-party Component CVEs More Information
Linux Kernel CVE-2026-31431, CVE-2026-43284, CVE-2026-43500 https://nvd.nist.gov/vuln/searchThis hyperlink is taking you to a website outside of Dell Technologies.

 

Dell Technologies recommande à tous les clients de prendre en compte à la fois le score de base CVSS et les scores temporels et environnementaux pertinents qui peuvent avoir un impact sur la gravité potentielle associée à une faille de sécurité donnée.

Produits concernés et mesure corrective

Product Affected Versions Remediated Versions Link
Dell Enterprise SONiC Distribution Versions prior to 4.5.3 Version 4.5.3 Link to update

 

Product Affected Versions Remediated Versions Link
Dell Enterprise SONiC Distribution Versions prior to 4.5.3 Version 4.5.3 Link to update

 

The Affected Products and Remediation table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.

Solutions de contournement et mesures d’atténuation

CVE ID Workaround and Mitigation
CVE-2026-31431, CVE-2026-43284, CVE-2026-43500

For customers who configure general Linux shell access or want to implement defense-in-depth measures, we recommend adding an additional filter to block dynamic loading of the affected modules.

1) Disable Vulnerable Kernel Module Loading

From the Linux shell as system admin add the following filter to your system configuration:

#Restrict loading of the affected kernel modules

echo "install algif_aead /bin/false" | sudo tee /etc/modprobe.d/disable-algif.conf

echo "install esp4 /bin/false" | sudo tee /etc/modprobe.d/disable-esp4.conf

echo "install rxrpc /bin/false" | sudo tee /etc/modprobe.d/disable-rxrpc.conf

If OSPFv3 IPSec authentication is not in use, apply the additional filter below as well:

echo "install esp6 /bin/false" | sudo tee /etc/modprobe.d/disable-esp6.conf

After applying the configuration, update module preferences:

sudo depmod -a

2) Verification

To verify the module is blocked:

#Check if any of the modules are active

lsmod | grep -E 'algif_aead|rxrpc|esp4|esp6'

#If necessary, unload the module if it is currently loaded

sudo modprobe -r <module_name>

#Attempt to load each module (should fail)

sudo modprobe algif_aead

#Expected output: modprobe: ERROR: ../libkmod/libkmod-module.c:1047 command_do() Error running install command '/bin/false' for module algif_aead: retcode 1

Persistence

The configuration will persist across system reboots. No additional steps are required.

 

Historique des révisions

RevisionDateDescription
1.02026-05-15Initial Release
2.02026-05-15Formatting changes only.  No changes to content.  
3.02026-06-10Link provided for the 4.5.3 release

 

Informations connexes

Produits concernés

Enterprise SONiC Distribution, PowerSwitch E3200-ON Series, PowerSwitch S3248T-ON, PowerSwitch S4348F/S4348T-ON, PowerSwitch S5212F-ON, PowerSwitch S5224F-ON, PowerSwitch S5232F-ON, PowerSwitch S5248F-ON, PowerSwitch S5296F-ON, PowerSwitch S5448F-ON , PowerSwitch Z9264F-ON, PowerSwitch Z9332F-ON, PowerSwitch Z9432F-ON, PowerSwitch Z9664F-ON, PowerSwitch Z9864F-ON ...
Propriétés de l’article
Numéro d’article: 000465379
Type d’article: Dell Security Advisory
Dernière modification: 10 Jun 2026
Trouvez des réponses à vos questions auprès d’autres utilisateurs Dell
Services de support
Vérifiez si votre appareil est couvert par les services de support.