logo

'Dirty Frag' Exploit Poised to Blow Up on Enterprise Linux Distros

ID: e8645422-fd2f-51d3-8cc1-6e364d92a3d5

STIX ID: report--e8645422-fd2f-51d3-8cc1-6e364d92a3d5

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: Elizabeth Montalbano

...
...

Dirty Frag is a Linux kernel vulnerability chain (CVE-2026-43284 and CVE-2026-43500) that allows local attackers to modify protected files in memory and escalate to root by abusing page-cache writes in the xfrm-ESP and rxrpc modules. A public proof-of-concept exists, patches are available for one CVE while the other is pending, several major distributions are affected, limited exploitation has been observed, and vendors and defenders are advised to apply mitigations (disable unused modules, harden local access) and prioritize kernel updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.