CVE-2026-43500 and CVE-2026-43284: Dirty Frag Linux Privilege Escalation Flaw Raises Post-Compromise Risk
ID: b1f7f160-8d9d-5491-8316-267099b9109d
STIX ID: report--b1f7f160-8d9d-5491-8316-267099b9109d
Feed Name: SOC Prime Blog
Dirty Frag (CVE-2026-43500 combined with CVE-2026-43284) is a Linux kernel RxRPC page-cache write flaw that allows an unprivileged local user — or an attacker with limited code execution via SSH, web shell, or container escape — to escalate to root by corrupting cached memory rather than on-disk files; Microsoft reports observed post-compromise abuse and Qualys provides a public PoC. The report details the vulnerability mechanics, visibility and detection gaps (memory-only changes), affected distributions, observed attacker behaviors, and interim mitigations including disabling rxrpc, hardening access, increasing telemetry, and applying vendor patches when available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
