Dirty Frag is a New Linux Exploit That Grants Root, and There's No Proper Patch Yet
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
A new Linux kernel privilege escalation exploit called Dirty Frag has been publicly disclosed ahead of schedule after an unnamed third party leaked it. It chains two CVEs (CVE-2026-43284 and CVE-2026-43500) to modify in-memory copies of system files without touching disk, ultimately granting root access. The first flaw targets /usr/bin/su via xfrm-ESP, while the second targets /etc/passwd via RxRPC. Together they cover most major Linux distributions. AlmaLinux has patched kernels in testing; all others should blacklist the esp4, esp6, and rxrpc kernel modules as an immediate mitigation and reboot once a proper patch is available.
9 Impressions