Dirty Frag (CVE-2026-43284, CVE-2026-43500): Frequently asked questions about this Linux kernel privilege escalation vulnerability chain
2026-05-08T20:52:24Z•f999e28d6ab34b5e7e291199f0d5056412976845e70a8f121d7347f816696ec8
CVECopy-FailDirty FragLPEdisclosure-timelinekernellinuxlocal-privilege-escalationpatchingpublic-exploit
What happened
Tenable RSO’s FAQ describes “Dirty Frag,” a chained Linux kernel local privilege escalation involving CVE-2026-43284 and CVE-2026-43500. The chain allows a local user to escalate to root; a public proof-of-concept exploit was released (May 7–8) before patches, and patched kernel versions are expected shortly. The chain extends the Copy Fail bug class and affects multiple Linux distributions running vulnerable kernels.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- tenable_blog
- Record identifier
- f999e28d6ab34b5e7e291199f0d5056412976845e70a8f121d7347f816696ec8
- Enrichment time
- 2026-05-08T20:52:24Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.