Dirty Frag: Using the Page Caches as an Attack Surface
2026-05-09T08:51:59Z•b6449a2a2377318c994fb4bfe1c4ec1e7081c41fcd2680bb1086ad4c8a7d4555
CVE-2026-43284CVE-2026-43500LPEMicrosoft DefenderOracle Critical Patch UpdatePatch TuesdayRedSundirty fraglinux kernellocal privilege escalationpage cachequalysvulnerability management
What happened
Feed highlights multiple high-risk vulnerability disclosures and patch updates. Dirty Frag is a Linux local privilege escalation (LPE) chain (published 2026-05-07) combining two kernel bugs that can allow an unprivileged local user to escalate to root on many major Linux distributions; CVE-2026-43284 was patched in mainline Linux (as of 2026-05-08) and public reporting referenced CVE-2026-43500. Separately, RedSun is a zero-day LPE in Microsoft Defender that enables low-privileged users to gain SYSTEM without a kernel exploit, leveraging a trusted, always-on component. The feed also notes high
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- qualys_blog
- Record identifier
- b6449a2a2377318c994fb4bfe1c4ec1e7081c41fcd2680bb1086ad4c8a7d4555
- Enrichment time
- 2026-05-09T08:51:59Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.