Dirty Frag Linux Vulnerability Let Attackers Gain Root Privileges – PoC Released
ID: 8004f087-e907-50c7-8105-db51c2b42ce7
STIX ID: report--8004f087-e907-50c7-8105-db51c2b42ce7
Feed Name: cybersecurityNews.com
Dirty Frag is a newly disclosed, CVE-pending Linux kernel local privilege escalation that combines two page-cache write flaws (xfrm-ESP and RxRPC) to deterministically obtain root on virtually all major Linux distributions; a public exploit surfaced after an embargo break on May 7, 2026. The report details how the flaws allow in-place modification of page-cache pages (e.g., /etc/passwd or /usr/bin/su), lists confirmed affected kernels/distributions, describes partial upstream patches and available module-blacklisting workarounds, and warns administrators to weigh IPsec/RxRPC impact until distribution backports are released.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
