Dirty Frag: Linux zero-day chains kernel flaws to grant root on major distros

1 min read
Source: BleepingComputer
Dirty Frag: Linux zero-day chains kernel flaws to grant root on major distros
Photo: BleepingComputer
TL;DR

A new Linux local privilege escalation called Dirty Frag chains two kernel page-cache write flaws (xfrm-ESP and RxRPC) to gain root on most major distributions; a PoC and full documentation were released after an embargo was breached. Patches are not yet available; mitigations involve disabling esp4, esp6, and rxrpc modules (which breaks IPsec VPNs). CVEs are CVE-2026-43284 and CVE-2026-43500; CISA warns about similar risks and urges patching and mitigation where possible.

Share this article

Want the full story? Read the original reporting

Read on BleepingComputer