CVE-2026-43500
“Dirty Frag” is a recently disclosed Linux kernel local privilege escalation (LPE) vulnerability that allows an unprivileged local user to obtain root access on many major Linux distributions. This includes a user logged in remotely via SSH. It belongs to the same class of page-cache corruption issues as Dirty Pipe and the more recent “Copy Fail” vulnerability. The vulnerability works by chaining two separate kernel flaws in the networking subsystem. Together, these flaws allow attackers to overwrite protected file contents in the Linux page cache without proper write permissions, ultimately enabling deterministic root privilege escalation. The issue has been fixed in the Linux kernel, but an official kernel release containing the patch has not yet been published. Most Linux distributions however have backported these patches to their kernels and started to make them available through updates. No in-the-wild exploitation has been reported to date. However, the similar “Copy Fail” vulnerability was exploited shortly after its public disclosure.
EPSS 92.86% · 99.8th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux kernel |
Timeline
- May 7, 2026 CVE Published
- May 8, 2026 PoC Published
- May 11, 2026 VulnCheck KEV Exploitation
- May 14, 2026 VulnCheck XDB Entry
- May 15, 2026 VulnCheck XDB Entry
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
- May 20, 2026 EPSS Score
- May 20, 2026 VulnCheck XDB Entry
- May 21, 2026 EPSS Score
- May 21, 2026 VulnCheck XDB Entry
- May 22, 2026 EPSS Score
References
- https://security-tracker.debian.org/tracker/CVE-2026-43284 advisory
- https://access.redhat.com/security/vulnerabilities/RHSB-2026-003 advisory
- https://ubuntu.com/blog/dirty-frag-linux-vulnerability-fixes-available advisory
- https://ccb.belgium.be/advisories/warning-dirty-frag-new-linux-local-privilege-escalation-vulnerability-was-disclosed advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-43284 vendor
- https://nvd.nist.gov/vuln/detail/CVE-2026-43500 vendor
- https://almalinux.org/blog/2026-05-07-dirty-frag/ vendor
- https://aws.amazon.com/security/security-bulletins/rss/2026-027-aws/ vendor
- https://www.wiz.io/blog/dirty-frag-linux-kernel-local-privilege-escalation-via-esp-and-rxrpc technical
- https://ccb.belgium.be/advisories/warning-copy-fail-getting-root-major-linux-distributions-patch-immediately technical