VU#980487: Local privilege escalation in Linux Kernel (Dirty Frag)
2026-05-26T20:52:13Z•61156b728ca9b7d1a33860e441aefdbb9ae4eeaa1a30a8bb006374b23de06c36
arbitrary-file-writedenial-of-servicednsmasqinformation-disclosurelinux-kernelmemory-corruptionmodel-securitynetwork-exposed-servicespath-traversalprivilege-escalationremote-code-executionserializationunauthenticated
What happened
This document aggregates multiple high-impact vulnerabilities disclosed in April–May 2026 affecting Linux kernels, networking daemons, identity platforms, LLM-serving frameworks, and model tooling. Notable issues include: "Dirty Frag" — an IPv4/IPv6 fragmentation/reassembly memory-corruption flaw (chaining CVE-2026-43284 and CVE-2026-43500) enabling kernel crashes and potential memory corruption; "Copy Fail" (CVE-2026-31431) — an AF_ALG/page-cache logic flaw allowing an unprivileged local 4-byte write into any readable file’s page cache (local root); SGLang RCE and path-traversal issues (CVE-‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- 61156b728ca9b7d1a33860e441aefdbb9ae4eeaa1a30a8bb006374b23de06c36
- Enrichment time
- 2026-05-26T20:52:13Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.