惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Recorded Future
Recorded Future
爱范儿
爱范儿
Y
Y Combinator Blog
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
腾讯CDC
罗磊的独立博客
阮一峰的网络日志
阮一峰的网络日志
Know Your Adversary
Know Your Adversary
P
Proofpoint News Feed
T
Tailwind CSS Blog
Attack and Defense Labs
Attack and Defense Labs
G
GRAHAM CLULEY
大猫的无限游戏
大猫的无限游戏
博客园 - Franky
C
Cyber Attacks, Cyber Crime and Cyber Security
T
The Blog of Author Tim Ferriss
T
The Exploit Database - CXSecurity.com
博客园 - 叶小钗
Latest news
Latest news
H
Hackread – Cybersecurity News, Data Breaches, AI and More
The Hacker News
The Hacker News
量子位
S
Security @ Cisco Blogs
Microsoft Security Blog
Microsoft Security Blog
Stack Overflow Blog
Stack Overflow Blog
美团技术团队
GbyAI
GbyAI
Google DeepMind News
Google DeepMind News
IT之家
IT之家
U
Unit 42
Project Zero
Project Zero
B
Blog
博客园 - 【当耐特】
D
DataBreaches.Net
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Hugging Face - Blog
Hugging Face - Blog
宝玉的分享
宝玉的分享
The Register - Security
The Register - Security
F
Full Disclosure
Vercel News
Vercel News
NISL@THU
NISL@THU
AWS News Blog
AWS News Blog
MongoDB | Blog
MongoDB | Blog
小众软件
小众软件
T
Threatpost
Martin Fowler
Martin Fowler
Engineering at Meta
Engineering at Meta
T
Tor Project blog
M
MIT News - Artificial intelligence
V
V2EX

Blog | Orca Security

Langflow RCE Actively Exploited to Deploy Cryptominers on AI Infrastructure Orca MCP: When Text Stops Scaling Kubernetes Compliance Tools: Automating CIS Benchmarks Risk-Based Vulnerability Management for the Cloud: A 2026 Guide Private Cloud Security: Top Risks and Best Practices (2026) What Is Generative AI in Cybersecurity? Best Vulnerability Management Tools and Software in 2026 2026 State of Application Security Report Recap: What the Data Says and What Security Teams Should Do About It AI Security for Sensitive Data: Best Practices and Guidelines Best AI Code Security Solutions 2026: How to Secure AI-Generated Code From Platform to Program: How to Ensure Your Cloud Security Solution Delivers Best AI Cybersecurity Providers 2026: A Buyer's Guide to AI-Powered Security Platforms Join Orca Security at Black Hat USA 2026 CNAPP Tools That Reduce Security Tool Sprawl: CNAPP vs. Dedicated Solutions What Is Container Runtime Security? A Practical Guide 2026 What Is Application Security Testing? Tools and Types What Is Managed Cloud Security? A Practical Guide What Is SaaS Security Posture Management? SSPM Guide Top 10 Cloud Security Standards for Compliance What is the MIT License? Compliance and Comparisons AI Agents vs. Agentless Security vs. Agent-based Security 144 Mastra npm Packages Compromised via Supply Chain Attack The Complete Guide to LLM Security: Risks, Best Practices, and Solutions Cloud Security LIVE 2026: Top 10 Takeaways Practitioners Can Use Now Cloud Security LIVE 2026: Top 10 Takeaways CISOs Can Use Now (and What to Do Next) How Orca Traced an nginx Flaw to 1.45 Million Tengine Servers All Running Vulnerable Code What to Look for in Container Security Tools Cloud Application Security Best Practices for DevSecOps Cloud Security Tools: 10 Types Explained for Teams What Is NIST CSF? Framework 2.0 Explained 7 Open Source Incident Response Tools by Category Critical Langflow Path Traversal Flaw Exploited for Unauthenticated RCE Critical PhpSpreadsheet RCE Patch Bypass Puts Millions at Risk Critical Splunk Enterprise Vulnerabilities Allow Unauthenticated File Operations and Remote Code Execution 16 Best Open Source Application Security Tools 2026 What Is Containerization? Security and Best Practices 8 Container Security Best Practices for 2026 Close the Cloud Identity Gap with Orca and AWS IAM Access Analyzer The 5-Step Context-Aware Cloud Vulnerability Prioritization Framework Critical Jupyter Enterprise Gateway Vulnerabilities Enable Full Kubernetes Cluster Takeover AI Security Best Practices for Regulated Industries Massive PyPI Supply Chain Attack Harvests Cloud Credentials via Python Startup Hooks SAST vs SCA: Key Differences for AppSec Teams What Is Cloud Security Architecture? Principles, Layers, and Frameworks What Is ASPM? A Guide to Application Security Posture Management What Is SaaS Security? A Practical Guide 2026 What Is a Man-in-the-Middle Attack? A Cloud Security Guide What Is Open Policy Agent? Best Practices and Use Cases 11 Best Open-Source DevSecOps Tools for 2026 How to Secure AI Workloads in Multi-Cloud Environments: A Complete Framework Critical WordPress Plugin Vulnerability Allows Unauthenticated Admin Takeover on 150K Sites What Is Kubernetes as a Service? KaaS Explained Critical Netlogon RCE Flaw Actively Exploited Against Windows Domain Controllers Your FedRAMP Continuous Monitoring Strategy Has a Gap. We Built Something to Fix It. How to Simplify Multi-Cloud Compliance Reporting: The 2026 Checklist Red Hat npm Packages Compromised in Supply-Chain Attack Spreading Credential-Stealing Worm Critical RCE in LiquidJS Lets Attackers Execute Arbitrary Commands on Unpatched Hosts Securing Shadow AI: How to Detect Unapproved LLMs in Your Cloud Data Security Posture Management (DSPM) for AI Gitea Container Registry Exposes Private Images to Unauthenticated Attackers Critical Unauthenticated RCE in Kopia Backup via SSH ProxyCommand Injection Best Palo Alto Networks Cortex (Prisma Cloud) Alternatives in 2026 7 Enterprise AI Security Risks to Manage Critical Pre-Auth RCE in ChromaDB Threatens AI Infrastructure Critical Coder Signature Bypass Exposes Developer Keys and Tokens New “PoolSlip” NGINX Exploit Revives Unpatched Remote Code Execution Risk Critical Drupal SQL Injection Exposes PostgreSQL-Backed Sites to Remote Code Execution AI Security Tools: How to Evaluate Them Across Every ML Attack Phase Massive npm Supply Chain Attack Compromises AntV Ecosystem, Steals CI/CD Secrets at Scale NIST AI Risk Management Framework (AI RMF) Explained: What It Is and How Organizations Use It The AI Data You Forgot to Lock: How Exposed Vector Databases Put Organizations at Risk GenAI Risks in Cloud Environments: What Security Teams Are Actually Missing in 2026 What Is Multi-Cloud Security? What Is Cloud Detection and Response (CDR)? Linux kernel vulnerability enables local theft of SSH host keys and /etc/shadow 18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated DoS and Potential RCE Announcing Cloud Security Agent Skills for Orca’s MCP Server TanStack and 160+ npm/PyPI Packages Compromised in Supply Chain Worm Attack Critical Apache HTTP Server HTTP/2 Vulnerability Could Enable Remote Code Execution Skill Issues: How We Discovered Supply Chain Attack Vectors in an AI Agent Skills Marketplace What Is an Incident Response Plan? What Is Cloud Data Security? Risks, Challenges, and 12 Best Practices Remote Code Execution in GitHub Enterprise Server via Git Push Injection (CVE-2026-3854) Linux Kernel Bug (Copy.Fail) Enables Local Privilege Escalation to Root (CVE-2026-31431) Xinference PyPI package compromise leads to full environment takeover What is Application Security? When AI Accelerates the Offense, Coverage Gaps Become Catastrophic Orca Security Recognized in the 2026 TAG Enterprise AI Security Handbook Navigating Cloud Security in 2026: Join Cloud Security LIVE Anthropic’s Project Glasswing Is a Positive Step Toward Cleaner, Safer Production Kyverno SSRF: Breaking Kubernetes Namespace Isolation (CVE-2026-4789) Streamline Compliance Reporting with Orca and Drata’s Integrated Vulnerability Management CVE-2026-23226: How a Missing Lock in ksmbd’s Channel List Exposes Your Linux SMB3 Server 2026 State of AppSec: When Development Velocity Outpaces Security AI Is Entering Your Infrastructure. Now what? Orca Security Featured in SACR’s 2026 Unified Agentic Defense Platforms Report Supply Chain Attack on Axios Delivers Cross-Platform RAT via Compromised npm Account Credential‑Stealing Malware in LiteLLM Supply Chain Attack Mission Accomplished: Orchestrate Your Remediation Strategy With Orca Missions The Orca Approach to Runtime AI Security
Dirty Frag: Linux Kernel Vulnerability Chain Enables Local Privilege Escalation to Root
Tohar Braun · 2026-05-11 · via Blog | Orca Security

Table of contents

  • Executive Summary
  • About the vulnerability: CVE-2026-43284 and CVE-2026-43500
  • Risk impact
  • Affected systems
  • Mitigation recommendations
  • Recommended actions:
  • How can Orca help?

Executive Summary

A Linux kernel vulnerability chain dubbed Dirty Frag has been disclosed, enabling a low-privileged local user to escalate privileges to root on affected Linux systems. The issue is especially relevant for cloud environments where attackers often gain an initial foothold through compromised credentials, vulnerable applications, CI/CD runners, containers, or exposed administrative services before attempting privilege escalation on the host. Reports of limited in-the-wild exploitation have started surfacing, involving suspicious su-based privilege escalation that may be associated with Dirty Frag or the recently disclosed Copy Fail vulnerability.

Dirty Frag is tracked as two related vulnerabilities: CVE-2026-43284, affecting the Linux kernel’s IPsec ESP path through esp4 and esp6, and CVE-2026-43500, affecting RxRPC. Together, these flaws can be chained to corrupt page-cache-backed memory and escalate privileges without modifying the file on disk.

About the vulnerability: CVE-2026-43284 and CVE-2026-43500

Dirty Frag belongs to the same broader page-cache corruption family as Dirty COW and Copy Fail, but it reaches the vulnerable condition through Linux networking components instead of the same crypto path used by Copy Fail. The vulnerability chain abuses kernel behavior in paths that process fragmented socket buffers, where pages that are not privately owned by the kernel may be modified in place. In practical terms, an attacker who already has local execution may be able to tamper with sensitive file contents as represented in memory, enabling root-level execution while leaving the underlying disk file unchanged.

The vulnerability is tracked as two separate CVEs because they cover different Linux deployment conditions. CVE-2026-43284, the ESP path issue, affects IPsec-related kernel modules and has been patched in mainline and stable kernel references. CVE-2026-43500 affects RxRPC, and vendor status varies by distribution.

Dirty Frag was disclosed after the coordinated disclosure timeline was disrupted, leading to public proof-of-concept availability before many distributions had completed patch rollout. Early reporting described the issue as broadly affecting major distributions, including Ubuntu, RHEL, Fedora, CentOS Stream, openSUSE, and AlmaLinux, while vendor advisories have since been updated with distribution-specific mitigation and patch guidance.

Risk impact

Successful exploitation could allow an attacker to gain root privileges on the affected Linux host. On non-containerized systems, this means full host compromise. In containerized environments, Ubuntu warns that the issue may also contribute to container escape scenarios where arbitrary third-party workloads are executed, although a container-escape proof of concept has not been published in its advisory.

The page-cache aspect also creates an important detection gap. Because the exploit can alter the in-memory representation of protected files rather than the file stored on disk, traditional file-integrity checks that rely only on disk hashes may miss signs of exploitation. Security teams should treat suspicious privilege escalation, unexpected execution of su, unusual kernel-module interactions, newly staged ELF binaries, and modifications to authentication-related files as high-priority investigation leads.

Affected systems

The full affected matrix depends on kernel version, distribution packaging, enabled modules, and vendor backports. Official advisories identify the vulnerable components as the Linux kernel modules used for IPsec ESP and RxRPC. Ubuntu stated that multiple Ubuntu releases were affected and assessed the issue as HIGH with a CVSS 3.1 score of 7.8, while Red Hat rated the issue Important and confirmed impact to RHEL 8, 9, 10, and OpenShift 4 during its ongoing investigation.

NVD lists CVE-2026-43284 as an issue in the Linux kernel’s ESP handling of shared socket-buffer fragments, with multiple stable-kernel patch references and a CISA-ADP CVSS 3.1 score of 7.8 HIGH.

Patch availability is moving quickly and differs by vendor. AlmaLinux, for example, updated its advisory to state that patched kernels were rolling out to production repositories on May 8, 2026, and published patched kernel version guidance for AlmaLinux 8, 9, and 10. Red Hat’s bulletin remains marked ongoing as of its May 9 update and includes mitigation guidance for affected products.

Mitigation recommendations

Organizations should prioritize kernel updates from their Linux distribution vendor. Where patched kernels are available, update and reboot into the fixed kernel as soon as operationally possible. Where patches are not yet available or cannot be deployed immediately, apply temporary mitigations after validating operational impact.

  1. Patch affected kernels using vendor-supported packages and reboot into the updated kernel.
  2. Temporarily block vulnerable modules where operationally safe. This generally means preventing esp4, esp6, and rxrpc from loading and unloading them if already active. Disabling esp4 and esp6 may disrupt IPsec or VPN functionality, while disabling rxrpc may affect AFS or other RxRPC-dependent environments.  
  3. Validate whether IPsec or RxRPC is in use before applying blanket mitigations in production. Red Hat notes that blocklisting ESP modules can break IPsec after reboot, and blocklisting RxRPC can break AFS client connectivity.  
  4. Restrict local execution paths by limiting unnecessary shell access, tightening SSH exposure, enforcing least privilege, and ensuring container workloads run with hardened security contexts.
  5. Harden container and Kubernetes environments by avoiding unnecessary capabilities such as CAP_NET_ADMIN, enforcing SELinux or AppArmor where applicable, using default-secure pod policies or security context constraints, and limiting debug access to trusted administrators.  
  6. Investigate suspected compromise before assuming patching alone is sufficient. Because the page cache can remain affected until cleared or the system is rebooted, systems suspected of exploitation should go through incident response, including memory-aware investigation, credential rotation, and reboot or cache-clearing steps consistent with vendor guidance. 

How can Orca help?

Orca enables customers to quickly identify cloud assets running affected Linux kernels, understand whether they are exposed in context, and prioritize remediation based on real-world risk rather than CVSS alone. This includes correlating vulnerable workloads with factors such as internet exposure, container hosting, privileged runtime settings, sensitive data access, identity risk, and asset criticality.

A screenshot of the Dirty Frag vulnerability being mention in the "From the News" section of the Orca platform
From the News in the Orca Platform