logo

CVE-2026-43500 and CVE-2026-43284: Dirty Frag Linux Privilege Escalation Flaw Raises Post-Compromise Risk

ID: b1f7f160-8d9d-5491-8316-267099b9109d

STIX ID: report--b1f7f160-8d9d-5491-8316-267099b9109d

Feed Name: SOC Prime Blog

Threat Score
80/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: SOC Prime Team

...
...

Dirty Frag (CVE-2026-43500 combined with CVE-2026-43284) is a Linux kernel RxRPC page-cache write flaw that allows an unprivileged local user — or an attacker with limited code execution via SSH, web shell, or container escape — to escalate to root by corrupting cached memory rather than on-disk files; Microsoft reports observed post-compromise abuse and Qualys provides a public PoC. The report details the vulnerability mechanics, visibility and detection gaps (memory-only changes), affected distributions, observed attacker behaviors, and interim mitigations including disabling rxrpc, hardening access, increasing telemetry, and applying vendor patches when available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.