New Linux 'Dirty Frag' Zero-Day Vulnerability Grants Root Access on Major Distros
A critical new zero-day vulnerability class named 'Dirty Frag' has been discovered in the Linux kernel, allowing attackers to obtain root privileges on all major Linux distributions. First reported by security researcher Hyunwoo Kim, this exploit chains two separate page-cache write vulnerabilities: one in xfrm-ESP (tracked as CVE-2026-43284) and another in RxRPC (tracked as CVE-2026-43500). Dirty Frag extends the bug class previously associated with Dirty Pipe and Copy Fail. Unlike many other exploits, it is a deterministic logic bug that does not rely on race conditions or specific timing windows, resulting in a very high success rate and preventing kernel panics upon failure. The embargo on this information was recently broken, meaning no official patches are currently available despite the assignment of CVE identifiers. This development poses a significant security risk to Linux systems globally, as it enables immediate privilege escalation. Technical details have been released publicly, urging administrators to monitor for upcoming security updates from distribution maintainers to mitigate this severe threat.
Wire timeline
New Linux 'Dirty Frag' Zero-Day Vulnerability Grants Root Access on Major Distros
A critical new zero-day vulnerability class named 'Dirty Frag' has been discovered in the Linux kernel, allowing attackers to obtain root privileges on all major Linux distributions. First reported by security researcher Hyunwoo Kim, this exploit chains two separate page-cache write vulnerabilities: one in xfrm-ESP (tracked as CVE-2026-43284) and another in RxRPC (tracked as CVE-2026-43500). Dirty Frag extends the bug class previously associated with Dirty Pipe and Copy Fail. Unlike many other exploits, it is a deterministic logic bug that does not rely on race conditions or specific timing windows, resulting in a very high success rate and preventing kernel panics upon failure. The embargo on this information was recently broken, meaning no official patches are currently available despite the assignment of CVE identifiers. This development poses a significant security risk to Linux systems globally, as it enables immediate privilege escalation. Technical details have been released publicly, urging administrators to monitor for upcoming security updates from distribution maintainers to mitigate this severe threat.
Slashdot