Linux Dirty Frag Hands Root Access
Linux kernels just got hit with Dirty Frag, a local root exploit chain popping up in attacks after public disclosure.
CVE-2026-43284 and CVE-2026-43500 chain flaws in xfrm-ESP IPsec and RxRPC code. Unprivileged users splice page cache pages into sockets, then trigger in-place decryption to overwrite setuid binaries like su. Microsoft spots limited in-the-wild activity.
Hits kernels from 4.10 to 7.0 across Ubuntu 24.04, RHEL 10, Fedora 44, AlmaLinux, Amazon Linux. Works on container hosts too, risks host escapes.
Researcher Hyunwoo Kim dropped working C PoC on github[.]com/V4bel/dirtyfrag before patches landed.
