VU#980487: Local privilege escalation in Linux Kernel (Dirty Frag)

2026-05-26T20:52:13Z61156b728ca9b7d1a33860e441aefdbb9ae4eeaa1a30a8bb006374b23de06c36
arbitrary-file-writedenial-of-servicednsmasqinformation-disclosurelinux-kernelmemory-corruptionmodel-securitynetwork-exposed-servicespath-traversalprivilege-escalationremote-code-executionserializationunauthenticated

What happened

This document aggregates multiple high-impact vulnerabilities disclosed in April–May 2026 affecting Linux kernels, networking daemons, identity platforms, LLM-serving frameworks, and model tooling. Notable issues include: "Dirty Frag" — an IPv4/IPv6 fragmentation/reassembly memory-corruption flaw (chaining CVE-2026-43284 and CVE-2026-43500) enabling kernel crashes and potential memory corruption; "Copy Fail" (CVE-2026-31431) — an AF_ALG/page-cache logic flaw allowing an unprivileged local 4-byte write into any readable file’s page cache (local root); SGLang RCE and path-traversal issues (CVE-‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
61156b728ca9b7d1a33860e441aefdbb9ae4eeaa1a30a8bb006374b23de06c36
Enrichment time
2026-05-26T20:52:13Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · VU#980487: Local privilege escalation in Linux Kernel (Dirty Frag) · Baitaphish