Dirty Frag: 9-year-old vulnerability enabling root access on Linux
ID: 63bef513-25af-5bcd-9a90-bf144902ce1d
STIX ID: report--63bef513-25af-5bcd-9a90-bf144902ce1d
Feed Name: ThreatLocker Blog
CVE-2026-43284 (xfrm-ESP) and CVE-2026-43500 (RxRPC), dubbed "Dirty Frag," are critical Linux kernel local privilege escalation vulnerabilities that abuse splice()-pinned page-cache references and in-place cryptographic operations to corrupt file-backed pages (e.g., /usr/bin/su), enabling arbitrary writes and full root escalation; the chain combines two separate flaws to improve reliability across distributions, no full patch was available at time of writing, and suggested mitigations include blacklisting affected modules and dropping the page cache.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
