---
schema: 1
kind: vulnerability
title: >
  CVE-2026-43284 / CVE-2026-43500 — Linux "Dirty Frag": deterministic LPE chain via page-cache
  write primitives in xfrm-ESP and RxRPC, active exploitation confirmed
headline: >
  CVE-2026-43284 / CVE-2026-43500 — Linux "Dirty Frag": deterministic LPE chain via page-cache
  write primitives in xfrm-ESP and RxRPC, active exploitation
summary: >
  "Dirty Frag" — two new Linux kernel LPE CVEs (CVE-2026-43284 / CVE-2026-43500), deterministic
  page-cache write chain, public PoC; active exploitation in limited campaigns confirmed by
  Microsoft; kernel patch for the rxrpc component still pending on all major distros. Mitigation:
  blacklist esp4, esp6, rxrpc kernel modules until distro patches land.
discovered_at: "2026-05-09T05:00:03Z"
updated_at: "2026-09-05T05:15:00Z"
event_date: 2026-05-08
run_id: 2026-05-09-migrated
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - lpe
  - actively-exploited
  - poc-public
  - patch-available
regions:
  - global
  - europe
  - switzerland
sectors: []
entities: ["trend:dirty-frag-linux-kernel-page-cache-lpe"]
techniques: [T1068, T1611]
affected_products: []
cves:
  - id: CVE-2026-43284
    cvss: "7.8"
    epss: "0.9324"
    type: lpe
    vector: local
    auth: post-auth
    status:
      - exploited
      - poc-public
      - patch-available
      - mitigation-only
  - id: CVE-2026-43500
    cvss: "7.8"
    epss: "0.9286"
    type: lpe
    vector: local
    auth: post-auth
    status:
      - exploited
      - poc-public
      - patch-available
      - mitigation-only
sources:
  - url: "https://www.wiz.io/blog/dirty-frag-linux-kernel-local-privilege-escalation-via-esp-and-rxrpc"
    publisher: "Wiz Research — Dirty Frag CVE-2026-43284/43500, 2026-05-08"
    role: primary
  - url: "https://www.microsoft.com/en-us/security/blog/2026/05/08/active-attack-dirty-frag-linux-vulnerability-expands-post-compromise-risk/"
    publisher: "Microsoft Security Blog, 2026-05-08"
    role: corroborating
  - url: "https://security-hub.ncsc.admin.ch/api/posts/12547/details"
    publisher: "NCSC-CH 12547, 2026-05-08"
    role: corroborating
  - url: "https://github.com/V4bel/dirtyfrag/blob/master/assets/write-up.md"
    publisher: "Researcher write-up (V4bel), 2026-05-07"
    role: corroborating
  - url: "https://www.helpnetsecurity.com/2026/05/08/dirty-frag-linux-vulnerability-cve-2026-43284-cve-2026-43500/"
    publisher: "Help Net Security, 2026-05-08"
    role: corroborating
  - url: "https://access.redhat.com/security/vulnerabilities/RHSB-2026-003"
    publisher: "Red Hat RHSB-2026-003, updated 2026-05-09"
    role: corroborating
  - url: "https://ccb.belgium.be/advisories/warning-dirty-frag-new-linux-local-privilege-escalation-vulnerability-was-disclosed"
    publisher: "CCB Belgium, 2026-05-08"
    role: corroborating
  - url: "https://access.redhat.com/security/vulnerabilities/RHSB-2026-003"
    publisher: "Red Hat (RHSB-2026-003), 2026-07-03"
    role: corroborating
  - url: "https://www.aikido.dev/blog/dirty-frag"
    publisher: "Aikido Security"
    date: "2026-09-04"
    role: corroborating
  - url: "https://api.first.org/data/v1/epss?cve=CVE-2026-43284,CVE-2026-43500"
    publisher: "FIRST.org EPSS API"
    date: "2026-09-04"
    role: corroborating
closed_sources: []
evidence:
  - quote: "Researcher Hyunwoo Kim disclosed \"Dirty Frag\" on 2026-05-07/08 after a third party inadvertently broke embargo by reverse-engineering the upstream patch."
    publisher: ctipilot v2 brief (migrated)
  - quote: "UPDATE (originally covered 2026-05-09): Microsoft Threat Intelligence published Active attack: Dirty Frag Linux vulnerability expands post-compromise risk on 2026-05-08 reporting \"limited in-the-wild activity where privilege escalation involving su is observed.\" The attack chain observed: SSH …"
    publisher: ctipilot v2 brief (migrated)
verification: multi-source
sourcing_note: >
  migration: evidence backfilled from v2 brief body (item predates the Evidence footer field).
  EPSS scores (FIRST.org, 2026-09-04) are 0.9324 for CVE-2026-43284 and 0.9286 for CVE-2026-43500 —
  both high, consistent with confirmed in-the-wild exploitation.
confidence: high
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: B
  credibility: 2
watchlist_hit: false
actions:
  - "Apply the distribution kernel update for CVE-2026-43284 and CVE-2026-43500, and separately confirm the related CVE-2026-46300 fix (tracked in its own entry) — Red Hat's applicability split means CVE-2026-43500 specifically does not affect RHEL, but CVE-2026-43284 and CVE-2026-46300 both do."
  - "Where immediate patching isn't possible: blacklist the `esp4`/`esp6`/`rxrpc` kernel modules (`modprobe -r esp4 esp6 rxrpc`; breaks IPsec/AFS if used) or disable unprivileged user namespaces (`kernel.unprivileged_userns_clone=0` on Ubuntu/Debian, `user.max_user_namespaces=0` on RHEL/CentOS) to block the CAP_NET_ADMIN acquisition path."
updates:
  - at: "2026-05-11T05:00:03Z"
    run_id: 2026-05-11-migrated
    type: update
    summary: >
      Dirty Frag Linux LPE now confirmed exploited in the wild — Microsoft Threat Intelligence reports
      "limited in-the-wild activity" involving su privilege escalation after SSH initial access
      (Microsoft Security Blog, 2026-05-08). Red Hat published RHSB-2026-003 with backports rolling
      out (Red Hat, updated 2026-05-09); NCSC.ch issued a Swiss federal advisory (NCSC-CH Security Hub
      post 12547, 2026-05-08).
    fields:
      - cves
      - evidence
      - regions
      - sources
      - body
    merged_from: 2026-05-11/dirty-frag-microsoft-confirms-limited-in-the-wild-exploitati
  - at: "2026-09-05T05:15:00Z"
    run_id: 2026-09-05T0409Z-intel
    type: update
    summary: >
      A related follow-on flaw, CVE-2026-46300 ("Fragnesia", tracked in its own entry), reopens
      this vulnerability's page-cache-write primitive on hosts patched only against CVE-2026-43284:
      a 13-year-old bug in the kernel's skb-coalescing code drops the shared-fragment marker the
      original fix relies on. Public Kubernetes-context proof-of-concept exploits now exist, and
      Red Hat confirms RHEL kernels need the CVE-2026-46300 fix too. EPSS scores (FIRST.org,
      2026-09-04) are now populated: 0.9324 for CVE-2026-43284 and 0.9286 for CVE-2026-43500.
    fields: [updated_at, cves, entities, classification, techniques, sources, actions, sourcing_note, body]
migrated_from: briefs/2026-05-09.md
---

Researcher Hyunwoo Kim disclosed "Dirty Frag" on 2026-05-07/08 after a third party inadvertently broke embargo by reverse-engineering the upstream patch. The chain exploits two page-cache write primitives: **CVE-2026-43284** (xfrm-ESP/IPsec subsystem, introduced ~2017, kernel mainline patch merged 2026-05-08) and **CVE-2026-43500** (RxRPC subsystem, introduced ~2023, patch still pending at disclosure). Unlike race-condition kernel exploits, this chain is deterministic and near-100% reliable: both primitives allow userland code to write arbitrary values into read-only page-cache pages (e.g., `/etc/passwd`, `/usr/bin/su`, setuid binaries) via memory aliasing caused by DMA remapping. The combined primitive produces a stable root primitive without timing windows. Exploitation requires `CAP_NET_ADMIN` — available by default in Linux user namespaces on Ubuntu, Fedora, and most Arch-based distributions; restricted on RHEL 8/9 and some hardened configs. Public PoC was published alongside disclosure. Microsoft Defender telemetry confirms limited active campaigns in which threat actors escalated from SSH-compromised user accounts, modified LDAP authentication files, exfiltrated PHP session contents, and disrupted active sessions ([Microsoft Security Blog, 2026-05-08](https://www.microsoft.com/en-us/security/blog/2026/05/08/active-attack-dirty-frag-linux-vulnerability-expands-post-compromise-risk/) · [Wiz Research, 2026-05-08](https://www.wiz.io/blog/dirty-frag-linux-kernel-local-privilege-escalation-via-esp-and-rxrpc) · [NCSC-CH advisory 12547, 2026-05-08](https://security-hub.ncsc.admin.ch/api/posts/12547/details)).

Affected distributions with confirmed exposure: Ubuntu 22.04/24.04/24.10, RHEL 8/9/10, Fedora, CentOS Stream, AlmaLinux, openSUSE Tumbleweed. Red Hat published RHSB-2026-003 ([Red Hat security bulletin](https://access.redhat.com/security/vulnerabilities/RHSB-2026-003)); Ubuntu published a fixes-available blog ([Ubuntu blog](https://ubuntu.com/blog/dirty-frag-linux-vulnerability-fixes-available)). Mitigation until patches land: `modprobe -r esp4 esp6 rxrpc` (breaks IPsec VPNs and AFS filesystems). This is a distinct chain from CVE-2026-31431 ("Copy Fail"), also by Kim, carrying its own separate CVE ids and code paths — though Red Hat's own bulletin notes the similarity is close enough that it refers to Dirty Frag as "Copy Fail 2" (see the 2026-09-05 update below).

**Detection:** Sysmon EID 1 / auditd `execve` on setuid binaries called from anomalous parent processes; EDR process ancestry anomalies for processes spawning as root from a non-root user context; unexpected writes to `/etc/passwd` or `/etc/shadow` detected via `auditctl -w /etc/passwd -p w`.

## Update — 2026-05-11T05:00:03Z

Microsoft Threat Intelligence published [`Active attack: Dirty Frag Linux vulnerability expands post-compromise risk`](https://www.microsoft.com/en-us/security/blog/2026/05/08/active-attack-dirty-frag-linux-vulnerability-expands-post-compromise-risk/) on 2026-05-08 reporting "limited in-the-wild activity where privilege escalation involving `su` is observed." The attack chain observed: SSH initial access → shell spawn → execution of an ELF binary that triggers the LPE primitive in either CVE-2026-43284 (xfrm-ESP page-cache write) or CVE-2026-43500 (RxRPC page-cache write). This is the first formal "exploited in the wild" attribution since the V4bel write-up published on 2026-05-07.

Red Hat published RHSB-2026-003 covering both CVEs on 2026-05-07 and updated it on 2026-05-09, with backported errata rolling out to RHEL 8/9/10 and OpenShift 4 ([Red Hat RHSB-2026-003](https://access.redhat.com/security/vulnerabilities/RHSB-2026-003)). NCSC.ch issued [Security Hub post 12547](https://security-hub.ncsc.admin.ch/api/posts/12547/details) on 2026-05-08 noting "Proof of Concept Available" and advising temporary blacklisting of the `esp4`, `esp6` and `rxrpc` kernel modules pending distribution backports. Belgium's CCB issued a parallel advisory ([CCB Belgium, 2026-05-08](https://ccb.belgium.be/advisories/warning-dirty-frag-new-linux-local-privilege-escalation-vulnerability-was-disclosed)).

The upstream xfrm-ESP fix merged on 2026-05-07 (kernel commit referenced by V4bel and corroborated by Red Hat); the RxRPC fix was still pending in the netdev tree at time of writing. AlmaLinux backported kernels on 2026-05-08; Ubuntu noted fixes will arrive via the kernel image package. Defender hunt focus: outbound SSH-to-unprivileged-shell-to-ELF-execution chains immediately followed by `setuid(0)` or `su` invocations, plus suspicious `setsockopt(AF_ALG)` patterns on the `esp4`/`esp6`/`rxrpc` modules followed by `splice()` syscalls into the page cache of read-only files. The Microsoft post emphasises that the page-cache write primitive bypasses on-disk file integrity monitoring (AIDE / IMA-EVM / auditd watch rules) — post-incident forensics must compare in-memory page contents against on-disk checksums, not just `md5sum` of the file.

Mitigation note (carried from 2026-05-09): on Ubuntu where unprivileged user namespaces are blocked by default, the `esp4`/`esp6` path is harder to reach because `CAP_NET_ADMIN` is required — but the RxRPC path remains exploitable without user-namespaces; the two CVEs are designed to complement each other. Where IPsec is in use, Red Hat suggests `kernel.unprivileged_userns_clone=0` (sysctl) as a less disruptive mitigation than full `esp4`/`esp6` module blacklisting. AFS users cannot blacklist `rxrpc` without losing AFS — wait for the distribution backport.

## Update — 2026-09-05T05:15:00Z

A related flaw, CVE-2026-46300 ("Fragnesia", tracked in its own entry), reopens this vulnerability's underlying page-cache-write primitive even on hosts already patched against CVE-2026-43284: a thirteen-year-old bug (dating to 2013) in the kernel's `skb_try_coalesce()` fails to preserve the marker that flags a fragment as page-cache-backed, which the original xfrm-ESP fix depends on to decide whether it is safe to decrypt in place ([Aikido Security](https://www.aikido.dev/blog/dirty-frag)). Red Hat's own security bulletin groups all three CVEs under the collective "Dirty Frag" name — noting the family's similarity to the earlier CVE-2026-31431 "Copy Fail" is close enough that Red Hat also refers to it as "Copy Fail 2", even though the two remain distinct CVEs with their own code paths — and confirms CVE-2026-46300 affects supported Red Hat Enterprise Linux kernels; administrators who patched only against CVE-2026-43284/CVE-2026-43500 should verify the CVE-2026-46300 fix is applied too ([Red Hat RHSB-2026-003](https://access.redhat.com/security/vulnerabilities/RHSB-2026-003)). Public proof-of-concept exploits for this family now target Kubernetes specifically, extending the exposure to container-shared-kernel environments beyond the bare-metal/VM case originally described ([Aikido Security](https://www.aikido.dev/blog/dirty-frag)).
