logo

Exploited in the Wild: “Dirty Frag” Linux Vulnerability Grants Instant Root Access

ID: fe9f0af3-8283-5cff-8b08-35be8743cb0b

STIX ID: report--fe9f0af3-8283-5cff-8b08-35be8743cb0b

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-09

Date Updated: 2026-05-22

Author: Ddos

...
...

Dirty Frag is a critical Linux local privilege escalation vulnerability affecting esp4, esp6, and rxrpc kernel modules (tracked as CVE-2026-43284 and CVE-2026-43500). Proof-of-concept exploits are circulating in the wild and the flaw allows an attacker with initial local access (SSH, web shell, container escape, or low-privileged account) to reliably escalate to root, evade detection, and persist across major enterprise distributions; recommended mitigations include disabling unused modules, assessing IPsec/esp impact, hardening local/container access, and verifying system integrity after suspected exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.