New DirtyClone Linux Vulnerability Allows Attackers to Gain Root Access Via Cloned Packets
ID: 4dc72790-53a6-5973-988d-360e79cc553c
STIX ID: report--4dc72790-53a6-5973-988d-360e79cc553c
Feed Name: cybersecurityNews.com
DirtyClone (CVE-2026-43503) is a high-severity Linux kernel local privilege-escalation vulnerability discovered by JFrog Security Research that allows unprivileged users to gain root by exploiting an skb packet-cloning path in the XFRM/IPsec subsystem which drops the SKBFL_SHARED_FRAG safety flag; it affects distributions with unprivileged user namespaces enabled, carries a CVSS score of 8.8, leaves no disk or kernel audit traces, and has been fixed in mainline with recommendations to update kernels, restrict user namespaces, blacklist unused IPsec modules, and drop page cache.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
