logo

Rushed Patches Follow Broken Embargo on New Linux Kernel Vulnerabilities

ID: 0c34d1ba-745d-5964-955f-9c80017a9e6b

STIX ID: report--0c34d1ba-745d-5964-955f-9c80017a9e6b

Feed Name: Infosecurity Magazine (News)

Threat Score
78/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

...
...

Dirty Frag is a chained local privilege escalation affecting major Linux distributions, formed by two high-severity Linux kernel flaws (CVE-2026-43284: write-what-where in xfrm-ESP, and CVE-2026-43500: out-of-bounds write in RxRPC). A PoC was published and Microsoft Defender observed limited in-the-wild privilege-escalation activity; maintainers and distributions are releasing patches and recommend temporary mitigations (disabling esp4/esp6/rxrpc modules) and monitoring for suspicious local privilege escalation behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.