logo

9-Year-Old Dirty Frag Vulnerability Enables Root Access on Linux Systems

ID: 8ecf2ad2-d58c-5536-bf95-9b03f507f05a

STIX ID: report--8ecf2ad2-d58c-5536-bf95-9b03f507f05a

Feed Name: HackRead

Threat Score
75/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: Deeba Ahmed

...
...

Red Hat and independent researchers disclosed "Dirty Frag", a pair of Linux kernel vulnerabilities (CVE-2026-43284 and CVE-2026-43500) that can be chained to achieve reliable local privilege escalation to root across many Linux distributions by abusing page-cache-write logic in IPSec ESP and RxRPC; mitigations include blacklisting affected modules, keeping SELinux enforcing, avoiding root workloads, and applying vendor patches when available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.