{
  "cves": [
    "CVE-2026-43284",
    "CVE-2026-43500"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[6.12.0-201.74.2.3]\n- rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present (Hyunwoo Kim)  [Orabug: 39342689]  {CVE-2026-43500}\n- rxrpc: Fix conn-level packet handling to unshare RESPONSE packets (David Howells)  [Orabug: 39342689] \n- rxrpc: only handle RESPONSE during service challenge (Wang Jie)  [Orabug: 39342689] \n- rxrpc: Fix rxrpc_input_call_event() to only unshare DATA packets (David Howells)  [Orabug: 39342689] \n- rxrpc: Fix potential UAF after skb_unshare() failure (David Howells)  [Orabug: 39342689] \n- rxrpc: Fix re-decryption of RESPONSE packets (David Howells)  [Orabug: 39342689] \n- xfrm: esp: avoid in-place decrypt on shared skb frags (Kuan-Ting Chen)  [Orabug: 39342689]  {CVE-2026-43284}",
  "id": "ELSA-2026-50259",
  "ovalId": "oval:com.oracle.elsa:def:202650259",
  "source": "oracle_linux",
  "title": "ELSA-2026-50259: Unbreakable Enterprise kernel security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2026-50259.html"
}