Multiple outlets report that a newly described Linux kernel local privilege escalation (LPE) vulnerability, dubbed “Dirty Frag,” enables local users to gain root privileges on major Linux distributions. The flaw is presented as an extension of earlier “Dirty” page-cache related bugs such as Copy Fail and Dirty Pipe. According to reports, Dirty Frag chains two page-cache write weaknesses: one involving the xfrm-ESP Page-Cache Write component and another involving the RxRPC Page-Cache Write component. Coverage notes that the exploit uses deterministic logic rather than a timing-based race window, and that it does not require the kernel to panic for the exploit to succeed.
Several outlets state that the embargo has ended and that the issues are tracked under CVE identifiers. The xfrm-ESP issue is associated with CVE-2026-43284, and the RxRPC issue is associated with CVE-2026-43500 (with one source describing it as reserved at the time of reporting). Reports also say that disclosure came before patches were broadly available for all affected components, and at least one outlet indicates limited exploitation may be occurring. Some sources mention that the vulnerability is “Copy Fail 2”-like in how it affects systems and why organizations should patch promptly.