Dirty Frag (CVE-2026-43284, CVE-2026-43500): Frequently asked questions about this Linux kernel privilege escalation vulnerability chain

2026-05-11T08:52:16Zc5ab4e397ad9af70ffff361e67d411f80a4b614dc1802b408cce39d390f7a73f
LPEcopy-faildirty-fragdisclosure-2026-05kernellinuxlocal-privilege-escalationproof-of-conceptpublic-exploittenablevulnerability-management

What happened

"Dirty Frag" is a chained Linux kernel local privilege escalation (LPE) vulnerability disclosed in early May 2026 that allows a local user to escalate to root. The chain consists of two tracked issues assigned CVE-2026-43284 and CVE-2026-43500. A public proof-of-concept exploit (GitHub) and technical details were released on May 7–8, 2026—before vendor patches were available. The exploit extends a bug class associated with the earlier “Copy Fail” kernel LPEs. Patched kernel versions are expected imminently; organizations should treat this as a high-severity local kernel LPE with available PoC.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
tenable_blog
Record identifier
c5ab4e397ad9af70ffff361e67d411f80a4b614dc1802b408cce39d390f7a73f
Enrichment time
2026-05-11T08:52:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.