logo

Dirty Frag Linux Vulnerability Exposes Major Distributions to Root Access Attacks

ID: 7741344b-03ae-5aa3-a7a1-00bc7d63fa28

STIX ID: report--7741344b-03ae-5aa3-a7a1-00bc7d63fa28

Feed Name: The Cyber Express

Threat Score
80/100

Date Published: 2026-05-08

Date Updated: 2026-05-08

Author: Ashish Khaitan

...
...

Dirty Frag is a newly disclosed, high-impact local privilege escalation (LPE) class affecting many major Linux distributions by chaining an xfrm-ESP Page-Cache Write flaw and an RxRPC Page-Cache Write flaw to obtain root. The vulnerability is deterministic (not race-based), a fully working proof-of-concept has been publicly released, and administrators are urged to disable affected kernel modules as a temporary mitigation until official patches are available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.