'Dirty Frag' Exploit Poised to Blow Up on Enterprise Linux Distros
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
A nine-year-old Linux kernel vulnerability dubbed 'Dirty Frag' has a public proof-of-concept exploit and may already be under limited active exploitation. The flaw chains two separate kernel bugs — CVE-2026-43284 and CVE-2026-43500 — in the IPsec ESP and rxrpc modules, enabling attackers to modify protected system files in memory and escalate privileges to root. It affects Ubuntu, RHEL, CentOS Stream, AlmaLinux, openSUSE Tumbleweed, and Fedora. Unlike Dirty Pipe and Copy Fail, Dirty Frag is a deterministic logic bug with no race condition requirement and a high success rate, making it more dangerous. Patches for CVE-2026-43284 are available from the Linux Kernel Organization, but CVE-2026-43500 remains unpatched. Mitigations include disabling unused rxrpc and IPsec modules, restricting local shell access, enforcing SELinux, and monitoring for abnormal privilege escalation.