logo

Panic at the Distro

ID: 11696a8f-e0a5-5921-acb6-4fef568a197a

STIX ID: report--11696a8f-e0a5-5921-acb6-4fef568a197a

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2026-05-14

Date Updated: 2026-05-18

...
...

This report details three related Linux kernel zero-copy vulnerabilities (CopyFail, Dirty Frag, and Fragnesia) that enable trivial local privilege escalation to root by corrupting the kernel page cache via zero-copy syscalls; public PoCs exist and most popular distributions were initially affected. It explains the technical mechanism, impacted kernel subsystems, discovery chronology, and provides remediation guidance (patching, module blacklisting, sysctl mitigations, and recommending LSM BPF), noting these require prior local access but are trivially exploitable once an attacker has a foothold.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.