Dirty Frag Linux Kernel Vulnerability Lets Attackers Gain Full Administrative Control
Image: ZDNET

Dirty Frag Linux Kernel Vulnerability Lets Attackers Gain Full Administrative Control

11 May, 2026.Technology and Science.20 sources

Dirty Frag is a local privilege escalation that grants root access. It chains with Copy Fail, enabling root access across major Linux distros.

20 outlets3 divides3 facts unevenly covered

Beat 1 · The verdict

Whether container escape is proven or merely possible

Full story

Dirty Frag Exploit Leaked

A nine-year-old Linux kernel vulnerability nicknamed "Dirty Frag" was publicly disclosed after an embargo broke, and it allows attackers with low-level access to gain full administrative control.

Because the embargo has currently been broken, no patch or CVE exists

Computing UKComputing UK

Hyunwoo Kim, who privately reported the issue to Linux maintainers on 30th April, said "Because the embargo has currently been broken, no patch or CVE exists," in a public post to the oss-security mailing list.

Image from Ars Technica
Ars TechnicaArs Technica

The flaw is tracked as two linked vulnerabilities, CVE-2026-43284 and CVE-2026-43500, and it chains weaknesses in the kernel’s networking subsystem to corrupt files held in memory without altering the originals stored on disk.

Red Hat confirmed the vulnerabilities affect its enterprise Linux products and classified the issue as "Important" severity, while Alma Linux and Ubuntu released patches or temporary mitigations within a day of public disclosure.

In response to the rapid succession of critical flaws, Linux stable kernel co-maintainer Sasha Levin proposed a "Killswitch" feature to disable vulnerable kernel functions while systems remain online until official patches can be deployed.

Limited Exploitation Signals

Dark Reading reported that a public exploit is available for the nine-year-old Dirty Frag flaw and that it may already be under limited exploitation, citing Microsoft Defender Security Research Team observations.

Elizabeth Montalbano’s Dark Reading account quoted the Microsoft Defender team: "Microsoft Defender is currently seeing limited in-the-wild activity where privilege escalation involving 'su' is observed," and said it may be indicative of techniques associated with either "Dirty Frag" or "Copy Fail."

Image from Computing UK
Computing UKComputing UK

Ars Technica said exploit code was leaked online three days ago and works reliably across virtually all Linux distributions, and it described the threat as deterministic and stealthy because it causes no crashes.

Ars Technica also said Microsoft has spotted signs that hackers are experimenting with Dirty Frag in the wild, and it described the exploit as chaining together code for CVE-2026-43284 and CVE-2026-43500.

Infosecurity Magazine added that Kim notified users of the Openwall Project’s open source security email thread on May 8 that the embargo had been broken before patches were ready, and it quoted Kim: "After consultation with the [Linux distributions] maintainers, and at the maintainers' request, I am publicly releasing this Dirty Frag document."

Patching, Mitigations, and Risk

As distributions moved to fix the two CVEs, Infosecurity Magazine said the Linux kernel security team disclosed two separate high-severity page-cache vulnerabilities on May 8, with CVE-2026-43284 rated 8.8 and CVE-2026-43500 rated 7.8.

CVE-2026-43284 has a severity rating (CVSS) of 8.8

Infosecurity MagazineInfosecurity Magazine

Until patches are available, Kim recommended disabling vulnerable kernel modules with a script that writes a modprobe configuration to install esp4, esp6, and rxrpc to /bin/false and then runs rmmod esp4 esp6 rxrpc.

ZDNET framed the moment as a security wake-up call by pointing to the rapid discovery of Copy Fail and Dirty Frag within a week and noting that a kill switch had been proposed to quickly disable affected functions until a patch is released.

SecurityWeek reported that Dirty Frag affects the xfrm-ESP (IPsec) and RxRPC components of the Linux kernel and said Ubuntu developers noted the container escape angle "has yet to be demonstrated."

Phoronix reported that Linux 7.0.6 was released to finish mitigating Dirty Frag, and it said the release is focused on a single patch for RXRPC, while Linux 6.18.29 LTS was also released with the same security fix.

Story read · 20 outlets · 3 disagreements · 3 facts unevenly covered

The divide · 1 of 3

Whether container escape is proven or merely possible

Changes how urgent container-exit remediation is for defenders.

Coverage map

How each outlet frames it

Every outlet we compared, the headline it ran, and a link to the original article.

Western Mainstream

Ars Technica
Ars Technica

Linux bitten by second severe vulnerability in as many weeks

11 May, 2026

Forbes
Forbes

Critical New Linux Zero-Day Leaked—What Admins Need To Do Now

11 May, 2026

The Hacker News
The Hacker News

New Linux 'Copy Fail' Vulnerability Enables Root Access on Major Distributions

05 May, 2026

Other

Computing UK
Computing UK

Nine-year-old high-severity Linux bug discovered

12 May, 2026

csoonline
csoonline

‘Trivial’ exploit can give attackers root access to Linux kernel

05 May, 2026

Dark Reading
Dark Reading

'Dirty Frag' Exploit Poised to Blow Up on Enterprise Linux Distros

11 May, 2026

HotHardware
HotHardware

Critical Copy Fail Linux Flaw Lets Hackers Gain Root Access Across Major Distros

05 May, 2026

Infosecurity Magazine
Infosecurity Magazine

Nine-Year-Old Zero-Day Flaw in Linux Kernel Discovered by AI-Equipped Security Researcher

05 May, 2026

Infosecurity Magazine
Infosecurity Magazine

Rushed Patches Follow Broken Embargo on New Linux Kernel Vulnerabilities

11 May, 2026

It's FOSS
It's FOSS

Should You Be Worried About The Copy Fail Linux Exploit?

07 May, 2026

iTnews
iTnews

'Copy Fail' Linux privesc bug lay dormant in kernel since 2017

05 May, 2026

Microsoft
Microsoft

CVE-2026-31431: Copy Fail vulnerability enables Linux root privilege escalation across cloud environments

05 May, 2026

Phoronix
Phoronix

Linux 7.0.6 Released To Finish Mitigating the Dirty Frag Vulnerability

11 May, 2026

Securelist
Securelist

Copy Fail: root on virtually any Linux

05 May, 2026

Security Affairs
Security Affairs

Copy Fail: New Linux bug enables Root via page‑cache corruption

05 May, 2026

SecurityWeek
SecurityWeek

New ‘Dirty Frag’ Linux Vulnerability Possibly Exploited in Attacks

11 May, 2026

The Record from Recorded Future News
The Record from Recorded Future News

Dirty Frag: Linux kernel hit by second major security flaw in two weeks

11 May, 2026

wiz.io
wiz.io

Copy Fail: Universal Linux Local Privilege Escalation Vulnerability

05 May, 2026

ZDNET
ZDNET

Linux is getting a security wake-up call - why it was inevitable and I'm not worried

11 May, 2026

Western Alternative

DiarioBitcoin
DiarioBitcoin

Linux 7.0.6 fixes Dirty Frag and closes a severe privilege escalation vector.

11 May, 2026

NewsCord Digest

Get every Technology and Science story like this one, in one email

Daily or weekly, only the topics you follow, each with the difference our analysis found across the outlets covering it.

Set up your digest

More on Technology and Science