Another Universal Linux Local Privilege Escalation (LPE) Vulnerability: Dirty Frag, (Fri, May 8th)

2026-05-09T01:23:46Z3b4e19764f9dc48e1a3fa5a5d2973fe22fc6c4099ff128f49b852be9e142dbfa
2026-05-08Copy FailDirty FragHyunwoo KimLPESANS ISCkernellinuxlocal privilege escalationmitigationprivilege escalationvulnerability disclosure

What happened

A new Linux kernel local privilege escalation (LPE) vulnerability dubbed "Dirty Frag" was disclosed on May 8, 2026 by Hyunwoo Kim (v4bel). It is another universal Linux LPE that is related to, and follows shortly after, the Copy Fail disclosure. System owners are advised to treat this as a high-risk local root escalation: apply vendor/kernel patches or mitigations when available, restrict untrusted local access, and follow vendor guidance (rebuild/reboot kernels, update distributions) to remediate.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
3b4e19764f9dc48e1a3fa5a5d2973fe22fc6c4099ff128f49b852be9e142dbfa
Enrichment time
2026-05-09T01:23:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.