BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Linux ‘Dirty Frag’ Vulnerability Unpatched

  • A new, unpatched Linux kernel vulnerability dubbed Dirty Frag enables local privilege escalation to root.
  • The flaw chains two Page-Cache Write bugs and has a high success rate, affecting major distributions like Ubuntu and RHEL.
  • A working proof-of-concept exploit is available, and mitigation involves blocking specific kernel modules until patches are released.

On May 8, 2026, security researcher Hyunwoo Kim disclosed a serious new local privilege escalation vulnerability in the Linux kernel, reported to maintainers just days earlier. Dubbed Dirty Frag, the flaw threatens most Linux distributions by allowing a local user to gain full root access.

- Advertisement -

This vulnerability is described as a successor to the actively exploited Copy Fail bug. “Dirty Frag is a case that extends the bug class to which Dirty Pipe and Copy Fail belong,” the researcher explained in a technical write-up.

It works by chaining the xfrm-ESP and RxRPC Page-Cache Write vulnerabilities. Consequently, the exploit does not depend on a timing race and has a very high success rate without causing kernel panic.

Successful exploitation impacts systems including Ubuntu 24.04.4, RHEL 10.1, and Fedora 44. The xfrm-ESP bug was introduced in a January 2017 commit, while the RxRPC bug came from a June 2023 commit.

However, the xfrm-ESP exploit requires creating a namespace, which Ubuntu blocks via AppArmor. Meanwhile, the RxRPC module is not included in distributions like RHEL but is loaded by default on Ubuntu.

- Advertisement -

By chaining the two, the blind spots cover each other across different environments. AlmaLinux said the bug decrypts directly over externally-backed pages, exposing or corrupting plaintext.

Adding urgency, a working proof-of-concept can gain root in a single command. Consequently, a mitigation involves blocking the esp4, esp6, and rxrpc modules until official patches are available.

It is worth noting that Dirty Frag works regardless of the algif_aead module’s status. Therefore, systems with the Copy Fail mitigation are still vulnerable to this new attack.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

U.S. Approves First Bitcoin Perpetual Futures

The U.S. Commodity Futures Trading Commission (CFTC) approved the nation's first regulated Bitcoin perpetual...

Arabic NLP Research Gains EdgeCloud GPU Support

Researchers at Cairo University leveraged distributed GPU compute via Theta EdgeCloud to overcome infrastructure...

Bitcoin Buy Orders Stack $500M Near Key $70K Zone

More than $500 million in buy orders is clustered between $72,000 and $70,000, creating...

Robinhood Stock Rallies on New AI Trading Agents

Robinhood shares surged 17% in 30 days, breaking from their tight correlation with declining...

Celsius Founder Seeks to Overturn 12-Year Prison Term

Alex Mashinsky filed a motion to vacate his 12-year prison sentence for fraud.His motion...

Must Read

9 Best Books On Ethereum And Blockchain Technology

QUICK LINKSHow to Choose Your First Blockchain Book: A Simple Framework1. Define Your Goal: Are you looking to Build, Invest, or Understand?2. Assess Your...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading