Dirty Frag: Linux zero-day chains kernel flaws to grant root on major distros

1 min read
Source: BleepingComputer
Dirty Frag: Linux zero-day chains kernel flaws to grant root on major distros
Photo: BleepingComputer
TL;DR Summary

A new Linux local privilege escalation called Dirty Frag chains two kernel page-cache write flaws (xfrm-ESP and RxRPC) to gain root on most major distributions; a PoC and full documentation were released after an embargo was breached. Patches are not yet available; mitigations involve disabling esp4, esp6, and rxrpc modules (which breaks IPsec VPNs). CVEs are CVE-2026-43284 and CVE-2026-43500; CISA warns about similar risks and urges patching and mitigation where possible.

Share this article

Reading Insights

Total Reads

0

Unique Readers

4

Time Saved

4 min

vs 5 min read

Condensed

91%

80471 words

Want the full story? Read the original article

Read on BleepingComputer