VDB

CVE-2026-43500

CVE-2026-43500 PUBLISHED CVSS 7.800000190734863 HIGH

“Dirty Frag” is a recently disclosed Linux kernel local privilege escalation (LPE) vulnerability that allows an unprivileged local user to obtain root access on many major Linux distributions. This includes a user logged in remotely via SSH. It belongs to the same class of page-cache corruption issues as Dirty Pipe and the more recent “Copy Fail” vulnerability. The vulnerability works by chaining two separate kernel flaws in the networking subsystem. Together, these flaws allow attackers to overwrite protected file contents in the Linux page cache without proper write permissions, ultimately enabling deterministic root privilege escalation. The issue has been fixed in the Linux kernel, but an official kernel release containing the patch has not yet been published. Most Linux distributions however have backported these patches to their kernels and started to make them available through updates. No in-the-wild exploitation has been reported to date. However, the similar “Copy Fail” vulnerability was exploited shortly after its public disclosure.

EPSS 40.27% · 97.4th percentile

Risk Scores

CVSS v3.0
7.800000190734863
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
40.27%
97.4th percentile

Affected Products

VendorProductVersions
LinuxLinux kernel

Timeline

  • May 8, 2026 CVE Published
  • May 18, 2026 EPSS Score
  • May 19, 2026 EPSS Score
  • May 20, 2026 EPSS Score
  • May 21, 2026 EPSS Score
  • May 22, 2026 EPSS Score
  • May 23, 2026 EPSS Score
  • May 24, 2026 EPSS Score
  • May 25, 2026 EPSS Score
  • May 26, 2026 EPSS Score
  • May 27, 2026 EPSS Score
  • May 28, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›