thehackernews.com 5/8/2026, 7:31:47 AM · via preferred

Dirty Frag kernel bug enables local root via chained exploits

Moxa Linux Flaw Lets Local Users Gain Root Access via Dirty Frag

Moxa has issued a critical security advisory (MPSA-263140) concerning vulnerabilities in its Linux-based operating systems that allow local attackers to gain root privileges. The weaknesses are identified as 'Copy Fail' (CVE-2026-31431) and 'Dirty Frag' (CVE-2026-43284, CVE-2026-43500). The advisory underscores the risks in non-containerized…

First seen 2026-05-01T21:21:17.916Z · Last seen 2026-05-27T10:32:00.184Z

CyberSIXT Evidence Panel
Primary Source openwall.com
CISA KEV Listed in KEV
Patch Patch Available

A new unpatched local privilege escalation in the Linux kernel, dubbed Dirty Frag, has been described as a successor to Copy Fail (CVE-2026-31431, CVSS 7.8) and was reported to Linux kernel maintainers on 30 April 2026. According to security researcher Hyunwoo Kim (@v4bel) the flaw enables root access by chaining the xfrm-ESP Page-Cache Write vulnerability with the RxRPC Page-Cache Write vulnerability, a deterministic bug that does not rely on a timing window.

Successful exploitation could grant an unprivileged local user elevated root privileges on most distributions, including Ubuntu 24.04.4, RHEL 10.1, openSUSE Tumbleweed, CentOS Stream 10, AlmaLinux 10 and Fedora 44.

The xfrm-ESP Page-Cache Write vulnerability originates from the IPSec (xfrm) subsystem and requires the attacker to create a user namespace, a step blocked by Ubuntu via AppArmor; in environments where this is allowed, the RxRPC module (rxrpc[.]ko) may be present to enable the attack, whereas on systems like Ubuntu the module is loaded by default. A PoC exists that can gain root in a single command, and administrators are advised to blockload esp4, esp6 and rxrpc by creating a dirtyfrag[.]conf entry.

View Primary Source Via thehackernews.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline