9-Year-Old Dirty Frag Vulnerability Enables Root Access on Linux Systems
ID: 8ecf2ad2-d58c-5536-bf95-9b03f507f05a
STIX ID: report--8ecf2ad2-d58c-5536-bf95-9b03f507f05a
Feed Name: HackRead
Threat Score
Red Hat and independent researchers disclosed "Dirty Frag", a pair of Linux kernel vulnerabilities (CVE-2026-43284 and CVE-2026-43500) that can be chained to achieve reliable local privilege escalation to root across many Linux distributions by abusing page-cache-write logic in IPSec ESP and RxRPC; mitigations include blacklisting affected modules, keeping SELinux enforcing, avoiding root workloads, and applying vendor patches when available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
