All incidents

DirtyClone Linux kernel privilege escalation (CVE-2026-43503)

vulnerabilityclosedJun 26, 2026 — Jun 29, 2026
DirtyClone Linux kernel privilege escalation (CVE-2026-43503)

JFROG Security Research has disclosed a high‑severity Linux kernel vulnerability tracked as CVE-2026-43503 that lets local users escalate to root privileges. The disclosure includes a technical write‑up and proof‑of‑concept code (available on their blog).

The flaw, scored 8.8 on the CVSS scale, stems from improper handling of cloned socket buffers in the networking subsystem (as reported by SecurityWeek). Attackers can abuse this to manipulate the page cache and overwrite executable binaries in memory, gaining root without leaving traces (per SecurityOnline).

The issue affects recent kernels shipped with Debian, Fedora and Ubuntu, particularly in shared environments such as multi‑tenant clouds and Kubernetes clusters (per SecurityAffairs). Although Ubuntu 24.04 includes mitigations that limit the attack vector, earlier releases remain exposed (per TheHackerNews).

No active exploitation or threat actor attribution has been reported, but a patch was released on 24 May to address the flaw (per JFrog). DirtyClone is the fourth variant in the DirtyFrag family, highlighting a persistent issue with socket buffer handling in the kernel (per SecurityWeek).

Administrators should apply the latest kernel update from their distribution as soon as possible (as advised by SecurityOnline). Where immediate patching is not feasible, disabling unprivileged user namespaces and blacklisting unused IPsec modules can reduce the risk (per SecurityAffairs).

Defenders should verify that affected systems are running a patched kernel and monitor for unexpected privilege escalation events (per TheHackerNews). Auditing namespace usage and reviewing container configurations can help detect attempts to exploit the flaw (per JFrog). Prioritising timely updates remains the most effective defence against this class of local privilege escalation (per SecurityWeek).

Intelligence briefing updated Jun 29, 2026

CVE-2026-43503 8.8
Root sourceresearch.jfrog.com
Timeline Coverage

Swipe to explore timeline