CVE-2026-43500
“Dirty Frag” is a recently disclosed Linux kernel local privilege escalation (LPE) vulnerability that allows an unprivileged local user to obtain root access on many major Linux distributions. This includes a user logged in remotely via SSH. It belongs to the same class of page-cache corruption issues as Dirty Pipe and the more recent “Copy Fail” vulnerability. The vulnerability works by chaining two separate kernel flaws in the networking subsystem. Together, these flaws allow attackers to overwrite protected file contents in the Linux page cache without proper write permissions, ultimately enabling deterministic root privilege escalation. The issue has been fixed in the Linux kernel, but an official kernel release containing the patch has not yet been published. Most Linux distributions however have backported these patches to their kernels and started to make them available through updates. No in-the-wild exploitation has been reported to date. However, the similar “Copy Fail” vulnerability was exploited shortly after its public disclosure.
EPSS 40.27% · 97.4th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux kernel |
Timeline
- May 8, 2026 CVE Published
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
- May 20, 2026 EPSS Score
- May 21, 2026 EPSS Score
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score
- May 25, 2026 EPSS Score
- May 26, 2026 EPSS Score
- May 27, 2026 EPSS Score
- May 28, 2026 EPSS Score
References
- https://ccb.belgium.be/advisories/warning-dirty-frag-new-linux-local-privilege-escalation-vulnerability-was-disclosed advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-43284 vendor
- https://nvd.nist.gov/vuln/detail/CVE-2026-43500 vendor
- https://almalinux.org/blog/2026-05-07-dirty-frag/ vendor
- https://aws.amazon.com/security/security-bulletins/rss/2026-027-aws/ vendor
- https://security-tracker.debian.org/tracker/CVE-2026-43284 vendor
- https://access.redhat.com/security/vulnerabilities/RHSB-2026-003 vendor
- https://ubuntu.com/blog/dirty-frag-linux-vulnerability-fixes-available vendor
- https://www.wiz.io/blog/dirty-frag-linux-kernel-local-privilege-escalation-via-esp-and-rxrpc technical
- https://ccb.belgium.be/advisories/warning-copy-fail-getting-root-major-linux-distributions-patch-immediately technical