Active attack: Dirty Frag Linux vulnerability expands post-compromise risk
ID: f16f215c-2f27-5347-b801-1fcc9d28da4d
STIX ID: report--f16f215c-2f27-5347-b801-1fcc9d28da4d
Feed Name: Microsoft Security
Date Published: 2026-05-08
Date Updated: 2026-05-11
Author: Microsoft Defender Security Research Team
Microsoft Defender describes “Dirty Frag,” a Linux kernel local privilege escalation that leverages esp4/esp6 and rxrpc networking/memory-fragment handling to reliably escalate from unprivileged user to root (CVE-2026-43284 and CVE-2026-43500). The report outlines technical behavior similar to CopyFail, observed limited in-the-wild usage after initial access (SSH, web-shells, container escape), detection coverage in Defender products, and mitigation recommendations including patching, disabling vulnerable modules, and increased monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
