
Dirty Frag Linux Kernel Vulnerability Lets Attackers Gain Full Administrative Control
Dirty Frag is a local privilege escalation that grants root access. It chains with Copy Fail, enabling root access across major Linux distros.
Beat 1 · The verdict
Whether container escape is proven or merely possible
Beat 2 · The divide, quote v quote
Full story
Dirty Frag Exploit Leaked
A nine-year-old Linux kernel vulnerability nicknamed "Dirty Frag" was publicly disclosed after an embargo broke, and it allows attackers with low-level access to gain full administrative control.
“Because the embargo has currently been broken, no patch or CVE exists”
Hyunwoo Kim, who privately reported the issue to Linux maintainers on 30th April, said "Because the embargo has currently been broken, no patch or CVE exists," in a public post to the oss-security mailing list.

The flaw is tracked as two linked vulnerabilities, CVE-2026-43284 and CVE-2026-43500, and it chains weaknesses in the kernel’s networking subsystem to corrupt files held in memory without altering the originals stored on disk.
Red Hat confirmed the vulnerabilities affect its enterprise Linux products and classified the issue as "Important" severity, while Alma Linux and Ubuntu released patches or temporary mitigations within a day of public disclosure.
In response to the rapid succession of critical flaws, Linux stable kernel co-maintainer Sasha Levin proposed a "Killswitch" feature to disable vulnerable kernel functions while systems remain online until official patches can be deployed.
Limited Exploitation Signals
Dark Reading reported that a public exploit is available for the nine-year-old Dirty Frag flaw and that it may already be under limited exploitation, citing Microsoft Defender Security Research Team observations.
Elizabeth Montalbano’s Dark Reading account quoted the Microsoft Defender team: "Microsoft Defender is currently seeing limited in-the-wild activity where privilege escalation involving 'su' is observed," and said it may be indicative of techniques associated with either "Dirty Frag" or "Copy Fail."

Ars Technica said exploit code was leaked online three days ago and works reliably across virtually all Linux distributions, and it described the threat as deterministic and stealthy because it causes no crashes.
Ars Technica also said Microsoft has spotted signs that hackers are experimenting with Dirty Frag in the wild, and it described the exploit as chaining together code for CVE-2026-43284 and CVE-2026-43500.
Infosecurity Magazine added that Kim notified users of the Openwall Project’s open source security email thread on May 8 that the embargo had been broken before patches were ready, and it quoted Kim: "After consultation with the [Linux distributions] maintainers, and at the maintainers' request, I am publicly releasing this Dirty Frag document."
Patching, Mitigations, and Risk
As distributions moved to fix the two CVEs, Infosecurity Magazine said the Linux kernel security team disclosed two separate high-severity page-cache vulnerabilities on May 8, with CVE-2026-43284 rated 8.8 and CVE-2026-43500 rated 7.8.
“CVE-2026-43284 has a severity rating (CVSS) of 8.8”
Until patches are available, Kim recommended disabling vulnerable kernel modules with a script that writes a modprobe configuration to install esp4, esp6, and rxrpc to /bin/false and then runs rmmod esp4 esp6 rxrpc.
ZDNET framed the moment as a security wake-up call by pointing to the rapid discovery of Copy Fail and Dirty Frag within a week and noting that a kill switch had been proposed to quickly disable affected functions until a patch is released.
SecurityWeek reported that Dirty Frag affects the xfrm-ESP (IPsec) and RxRPC components of the Linux kernel and said Ubuntu developers noted the container escape angle "has yet to be demonstrated."
Phoronix reported that Linux 7.0.6 was released to finish mitigating Dirty Frag, and it said the release is focused on a single patch for RXRPC, while Linux 6.18.29 LTS was also released with the same security fix.
Story read · 20 outlets · 3 disagreements · 3 facts unevenly covered
Keep reading
Trump Signs Executive Order Spacing Out Childhood Vaccines, Splitting MMR Into Three Shots
how 15 outlets framed it →
Trump Signs Executive Order Spacing Out Childhood Vaccines Into Separate Visits
how 12 outlets framed it →
7.4 Earthquake Kills At Least 71 In Western Colombia, Traps People In Collapsed Buildings
27 sources compared →
The divide · 1 of 3
Whether container escape is proven or merely possible
“this yet to be demonstrated, Ubuntu developers noted”
Read at source →“can be used to escape from cloud containers”
Read at source →Changes how urgent container-exit remediation is for defenders.
Coverage map
Other (16)
Western Mainstream (3)
Western Alternative (1)
How each outlet frames it
Every outlet we compared, the headline it ran, and a link to the original article.
Western Mainstream
Linux bitten by second severe vulnerability in as many weeks
11 May, 2026
New Linux 'Copy Fail' Vulnerability Enables Root Access on Major Distributions
05 May, 2026
Other
‘Trivial’ exploit can give attackers root access to Linux kernel
05 May, 2026
'Dirty Frag' Exploit Poised to Blow Up on Enterprise Linux Distros
11 May, 2026
Critical Copy Fail Linux Flaw Lets Hackers Gain Root Access Across Major Distros
05 May, 2026
Nine-Year-Old Zero-Day Flaw in Linux Kernel Discovered by AI-Equipped Security Researcher
05 May, 2026
Rushed Patches Follow Broken Embargo on New Linux Kernel Vulnerabilities
11 May, 2026
CVE-2026-31431: Copy Fail vulnerability enables Linux root privilege escalation across cloud environments
05 May, 2026
Linux 7.0.6 Released To Finish Mitigating the Dirty Frag Vulnerability
11 May, 2026
Copy Fail: New Linux bug enables Root via page‑cache corruption
05 May, 2026
New ‘Dirty Frag’ Linux Vulnerability Possibly Exploited in Attacks
11 May, 2026
Dirty Frag: Linux kernel hit by second major security flaw in two weeks
11 May, 2026
Copy Fail: Universal Linux Local Privilege Escalation Vulnerability
05 May, 2026
Linux is getting a security wake-up call - why it was inevitable and I'm not worried
11 May, 2026
Western Alternative
Linux 7.0.6 fixes Dirty Frag and closes a severe privilege escalation vector.
11 May, 2026
NewsCord Digest
Get every Technology and Science story like this one, in one email
Daily or weekly, only the topics you follow, each with the difference our analysis found across the outlets covering it.
Set up your digestMore on Technology and Science

Trump Signs Executive Order Spacing Out Childhood Vaccines, Splitting MMR Into Three Shots
15 sources compared
Trump Signs Executive Order Spacing Out Childhood Vaccines Into Separate Visits
12 sources compared

7.4 Earthquake Kills At Least 71 In Western Colombia, Traps People In Collapsed Buildings
27 sources compared

Valve Notifies European Steam Hardware Buyers After CEVA Logistics Cyberattack Exposed Personal Data
13 sources compared