Summary DirtyFrag is a Linux local privilege escalation disclosed on May 7, 2026, exploiting two kernel page-cache write vulnerabilities–CVE-2026-43284 (xfrm-ESP, patched in mainline only) and CVE-2026-43500 (RxRPC, no patch merged into any kernel tree as of disclosure)–that affect every major Linux distribution: Ubuntu, RHEL, Fedora, CentOS Stream, AlmaLinux, and openSUSE. Both bugs belong to the […]