The Lab · 2026-05-08 17:24:44 · GitHub Issues
A cluster of critical Linux kernel vulnerabilities has surfaced this week with no available patches, creating an immediate and active threat landscape for systems worldwide. The most severe disclosure—Dirty Frag—has been identified as a universal Linux Local Privilege Escalation (LPE) zero-day. The vulnerability was di...
The Lab · 2026-05-08 21:54:53 · Microsoft Security Blog
A newly disclosed Linux local privilege escalation vulnerability dubbed "Dirty Frag" is under active exploitation, enabling attackers to escalate from unprivileged user to root through vulnerable kernel networking and memory-fragment handling components. The flaw affects esp4 and esp6 components (CVE-2026-43284) and rx...
The Lab · 2026-05-09 22:31:47 · Mastodon:mastodon.social:#cybersecurity
A newly disclosed vulnerability cataloged as CVE-2026-43284—dubbed "Dirty Frag"—has surfaced as the second Linux kernel privilege-escalation exploit to emerge in an eight-day window, raising fresh scrutiny over kernel-level attack surface and the pace of coordinated vulnerability disclosure in open-source infrastructur...
The Lab · 2026-05-11 08:40:30 · GitHub Issues
Une vulnérabilité critique de type Local Privilege Escalation, désignée CVE-2026-43284 et connue sous le nom Dirty Frag, a été divulguée le 7 mai 2026. Elle affecte les modules noyau Linux `esp4` et `esp6`, responsables du traitement IPsec ESP utilisé par des solutions VPN telles que StrongSwan ou le fallback WireGuard...
The Lab · 2026-05-11 12:10:34 · SecurityWeek RSS
Security researchers have identified a critical Linux kernel vulnerability, internally referred to as "Dirty Frag" and also known as "Copy Fail 2," tracked under CVE-2026-43284 and CVE-2026-43500. The flaw was publicly disclosed before a corresponding security patch became available, raising urgent concerns within the ...
The Lab · 2026-05-13 08:48:29 · Mastodon:hachyderm.io:#infosec
Linux kernel maintainers have proposed a new runtime disable mechanism, called "Killswitch," that would allow administrators to immediately deactivate vulnerable kernel subsystems while patches are built, tested, and deployed. The initiative directly addresses the operational gap that leaves production systems exposed ...
The Lab · 2026-05-13 09:48:26 · GitHub Issues
Scaleway has issued a security advisory addressing CVE-2026-43284, a Linux kernel local privilege escalation vulnerability affecting the ESP IPsec transform modules (`esp4`/`esp6`) and the AF_RXRPC socket family (`rxrpc`). The flaw mirrors the threat shape of CVE-2026-31431 (Copy Fail), allowing a local unprivileged us...
The Lab · 2026-05-14 18:18:20 · The Register
Security researchers at Wiz have disclosed "Fragnesia," a critical Linux kernel local privilege escalation vulnerability that permits unprivileged users to obtain root-level access by corrupting page cache memory. Tracked as CVE-2026-46300, the flaw was discovered by William Bowling of the V12 security team and resides...