Dirty Frag: Unpatched Linux Vulnerability Grants Root Access
A critical local privilege escalation vulnerability dubbed 'Dirty Frag' has been disclosed in the Linux kernel, allowing attackers to gain root access. The issue comprises two distinct flaws: a patched xfrm-ESP Page-Cache Write vulnerability (CVE-2026-43284) and an currently unpatched RxRPC Page-Cache Write vulnerability (CVE-2026-43500). Researcher Hyunwoo Kim reported both issues, but a third-party leak of exploit details during the embargo period forced early public disclosure before fixes were widely available. Consequently, major distributions including Red Hat, Ubuntu, and Debian remain vulnerable to the unpatched component. Security experts warn that chaining these two flaws creates a reliable exploit for immediate root escalation. Administrators are urgently advised to mitigate risks by blacklisting or unloading the affected kernel modules until official patches are released and applied. This incident follows closely after the 'Copy Fail' vulnerability, highlighting ongoing security challenges within the Linux networking stack. Users are encouraged to address both vulnerabilities simultaneously due to their similar mitigation strategies and potential for combined exploitation.
Wire timeline
Dirty Frag: Unpatched Linux Vulnerability Grants Root Access
A critical local privilege escalation vulnerability dubbed 'Dirty Frag' has been disclosed in the Linux kernel, allowing attackers to gain root access. The issue comprises two distinct flaws: a patched xfrm-ESP Page-Cache Write vulnerability (CVE-2026-43284) and an currently unpatched RxRPC Page-Cache Write vulnerability (CVE-2026-43500). Researcher Hyunwoo Kim reported both issues, but a third-party leak of exploit details during the embargo period forced early public disclosure before fixes were widely available. Consequently, major distributions including Red Hat, Ubuntu, and Debian remain vulnerable to the unpatched component. Security experts warn that chaining these two flaws creates a reliable exploit for immediate root escalation. Administrators are urgently advised to mitigate risks by blacklisting or unloading the affected kernel modules until official patches are released and applied. This incident follows closely after the 'Copy Fail' vulnerability, highlighting ongoing security challenges within the Linux networking stack. Users are encouraged to address both vulnerabilities simultaneously due to their similar mitigation strategies and potential for combined exploitation.
Help Net Security