logo

Dirty Frag: Linux Kernel Local Privilege Escalation via ESP and RxRPC

ID: d6b3703f-9e27-5a12-bbe7-b49a2dd97949

STIX ID: report--d6b3703f-9e27-5a12-bbe7-b49a2dd97949

Feed Name: Wiz Blog

Threat Score
75/100

Date Published: 2026-05-08

Date Updated: 2026-05-08

Author: Merav Bar

...
...

A newly disclosed Linux kernel local privilege escalation chain called `Dirty Frag` (CVE-2026-43284, CVE-2026-43500) combines page-cache write primitives in the xfrm-ESP (IPsec) and RxRPC subsystems to enable deterministic, reliable corruption of page-backed memory and local root escalation; a public proof-of-concept exists, multiple major distributions and kernel versions are affected, and mitigations (module blacklisting, hardening local access, monitoring) are recommended until patches are available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.