VU#980487: Local privilege escalation in Linux Kernel (Dirty Frag)
2026-05-21T08:52:15Z•4ed8215acc48ac6d8594849ab8e7b150dfd7a3b3b1ced263b435be6440dc2646
arbitrary-file-writecasdoorcopy-faildenial-of-servicedirty-fragdnsmasqdrc-insightggufheap-out-of-boundsinformation-disclosurelinux-kernellocal-privilege-escalationmemory-corruptionollamapath-traversalquantizationremote-code-executionsglangunauthenticated-modification
What happened
Multiple high-impact vulnerabilities were disclosed across diverse projects. Key issues include: (1) Linux kernel fragmentation reassembly flaw (“Dirty Frag”) leading to memory corruption and potential DoS or exploitation (chains CVE-2026-43284 and CVE-2026-43500); (2) another Linux kernel local privilege escalation (“Copy Fail”, CVE-2026-31431) allowing controlled in-memory writes to reach root; (3) SGLang multimodal runtime with two RCEs and a path-traversal (CVE-2026-7301, CVE-2026-7304, CVE-2026-7302) enabling remote code execution or arbitrary file writes when exposed; (4) dnsmasq with多个内
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- 4ed8215acc48ac6d8594849ab8e7b150dfd7a3b3b1ced263b435be6440dc2646
- Enrichment time
- 2026-05-21T08:52:15Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.