logo

Dirty Frag Linux Vulnerability Let Attackers Gain Root Privileges – PoC Released

ID: 8004f087-e907-50c7-8105-db51c2b42ce7

STIX ID: report--8004f087-e907-50c7-8105-db51c2b42ce7

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-05-08

Date Updated: 2026-05-08

Author: Guru Baran

...
...

Dirty Frag is a newly disclosed, CVE-pending Linux kernel local privilege escalation that combines two page-cache write flaws (xfrm-ESP and RxRPC) to deterministically obtain root on virtually all major Linux distributions; a public exploit surfaced after an embargo break on May 7, 2026. The report details how the flaws allow in-place modification of page-cache pages (e.g., /etc/passwd or /usr/bin/su), lists confirmed affected kernels/distributions, describes partial upstream patches and available module-blacklisting workarounds, and warns administrators to weigh IPsec/RxRPC impact until distribution backports are released.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.