Ubuntu has released fixes for DirtyClone (CVE-2026-43503), a HIGH severity (CVSS 8.8) Linux kernel local privilege escalation vulnerability. First disclosed responsibly to kernel maintainers and published May 23, 2026, the vulnerability affects all Ubuntu releases and was publicly detailed by JFrog on June 25, 2026. Beyond local privilege escalation, it can also enable container escape in environments running arbitrary third-party workloads. Fixes are available for Ubuntu 20.04 LTS (HWE kernel), 22.04 LTS, 24.04 LTS, 25.10, and 26.04 LTS. Systems that previously applied mitigations for the related Dirty Frag or Fragnesia vulnerabilities are already protected. Users are advised to run `sudo apt update && sudo apt upgrade` and reboot.

3m read timeFrom ubuntu.com
Post cover image
Table of contents
ImpactAffected releasesHow to check if you are impactedSecurity updates