Another Universal Linux Local Privilege Escalation (LPE) Vulnerability: Dirty Frag, (Fri, May 8th)
2026-05-09T01:23:46Z•3b4e19764f9dc48e1a3fa5a5d2973fe22fc6c4099ff128f49b852be9e142dbfa
2026-05-08Copy FailDirty FragHyunwoo KimLPESANS ISCkernellinuxlocal privilege escalationmitigationprivilege escalationvulnerability disclosure
What happened
A new Linux kernel local privilege escalation (LPE) vulnerability dubbed "Dirty Frag" was disclosed on May 8, 2026 by Hyunwoo Kim (v4bel). It is another universal Linux LPE that is related to, and follows shortly after, the Copy Fail disclosure. System owners are advised to treat this as a high-risk local root escalation: apply vendor/kernel patches or mitigations when available, restrict untrusted local access, and follow vendor guidance (rebuild/reboot kernels, update distributions) to remediate.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 3b4e19764f9dc48e1a3fa5a5d2973fe22fc6c4099ff128f49b852be9e142dbfa
- Enrichment time
- 2026-05-09T01:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.