logo

Dirty Frag: Using the Page Caches as an Attack Surface

ID: 753fe501-0585-5718-b213-4c6b810f438b

STIX ID: report--753fe501-0585-5718-b213-4c6b810f438b

Feed Name: Qualys Blog

Threat Score
80/100

Date Published: 2026-05-09

Date Updated: 2026-05-11

Author: Mayuresh Dani

...
...

Dirty Frag is a disclosed Linux local privilege escalation (LPE) chain (CVE-2026-43284 and CVE-2026-43500) that leverages page-cache writes into skb frags to allow unprivileged users to gain root on many major distributions; public exploit code targets /etc/passwd and patches and Qualys QIDs have been released for mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.