logo

New Linux 'Dirty Frag' zero-day gives root on all major distros

ID: 557bffa1-343f-5d63-921d-ad2876e3f529

STIX ID: report--557bffa1-343f-5d63-921d-ad2876e3f529

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-05-08

Date Updated: 2026-05-08

Author: Sergiu Gatlan

...
...

Dirty Frag is a newly disclosed Linux zero-day local privilege escalation that chains two kernel page-cache write flaws in the algif_aead interface to modify protected memory and obtain root on most major distributions; a public proof-of-concept was released after an embargo was broken and vendors have not yet published patches. Recommended mitigation is to remove the vulnerable esp4/esp6/rxrpc kernel modules (which will break IPsec VPNs and AFS), and the issue currently lacks a CVE and widespread vendor fixes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.