A new Linux kernel privilege escalation exploit called Dirty Frag has been publicly disclosed ahead of schedule after an unnamed third party leaked it. It chains two CVEs (CVE-2026-43284 and CVE-2026-43500) to modify in-memory copies of system files without touching disk, ultimately granting root access. The first flaw targets /usr/bin/su via xfrm-ESP, while the second targets /etc/passwd via RxRPC. Together they cover most major Linux distributions. AlmaLinux has patched kernels in testing; all others should blacklist the esp4, esp6, and rxrpc kernel modules as an immediate mitigation and reboot once a proper patch is available.

3m read timeFrom feed.itsfoss.com
Post cover image
Table of contents
What is Dirty Frag?What can you do?
9 Impressions