VU#980487: Local privilege escalation in Linux Kernel (Dirty Frag)

2026-05-21T08:52:15Z4ed8215acc48ac6d8594849ab8e7b150dfd7a3b3b1ced263b435be6440dc2646
arbitrary-file-writecasdoorcopy-faildenial-of-servicedirty-fragdnsmasqdrc-insightggufheap-out-of-boundsinformation-disclosurelinux-kernellocal-privilege-escalationmemory-corruptionollamapath-traversalquantizationremote-code-executionsglangunauthenticated-modification

What happened

Multiple high-impact vulnerabilities were disclosed across diverse projects. Key issues include: (1) Linux kernel fragmentation reassembly flaw (“Dirty Frag”) leading to memory corruption and potential DoS or exploitation (chains CVE-2026-43284 and CVE-2026-43500); (2) another Linux kernel local privilege escalation (“Copy Fail”, CVE-2026-31431) allowing controlled in-memory writes to reach root; (3) SGLang multimodal runtime with two RCEs and a path-traversal (CVE-2026-7301, CVE-2026-7304, CVE-2026-7302) enabling remote code execution or arbitrary file writes when exposed; (4) dnsmasq with多个内

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
4ed8215acc48ac6d8594849ab8e7b150dfd7a3b3b1ced263b435be6440dc2646
Enrichment time
2026-05-21T08:52:15Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.