logo

Active attack: Dirty Frag Linux vulnerability expands post-compromise risk

ID: f16f215c-2f27-5347-b801-1fcc9d28da4d

STIX ID: report--f16f215c-2f27-5347-b801-1fcc9d28da4d

Feed Name: Microsoft Security

Threat Score
72/100

Date Published: 2026-05-08

Date Updated: 2026-05-11

Author: Microsoft Defender Security Research Team

...
...

Microsoft Defender describes “Dirty Frag,” a Linux kernel local privilege escalation that leverages esp4/esp6 and rxrpc networking/memory-fragment handling to reliably escalate from unprivileged user to root (CVE-2026-43284 and CVE-2026-43500). The report outlines technical behavior similar to CopyFail, observed limited in-the-wild usage after initial access (SSH, web-shells, container escape), detection coverage in Defender products, and mitigation recommendations including patching, disabling vulnerable modules, and increased monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.