The recently disclosed Linux kernel “Dirty Frag” local privilege escalation issue is an important reminder that kernel-level vulnerabilities can have serious impact, especially on systems where untrusted users have local shell access.
As per public reporting, Dirty Frag is a local privilege escalation vulnerability class that chains issues in the Linux kernel networking subsystems, specifically involving xfrm-ESP and RxRPC, and may allow an unprivileged local user to gain root privileges on affected systems. The issue has been reported against several modern Linux distributions, including Ubuntu 24.04.4, RHEL 10.1, CentOS Stream 10, AlmaLinux 10, Fedora 44, and openSUSE Tumbleweed.
This is not a remote network exploit by itself. Red Hat also describes Dirty Frag as a local privilege escalation issue where a user with a local account could trigger the flaw to gain root privileges. We recommend that all organizations continue to restrict local shell access, limit administrative privileges, keep systems updated, and monitor vendor advisories for confirmed patches or mitigations.

Details have emerged about a new, unpatched local privilege escalation (LPE) vulnerability impacting the Linux kernel. Dubbed Dirty Frag, it has been described as a successor to Copy Fail (CVE-2026-31431, CVSS score: 7.8), a recently disclosed LPE flaw impacting the Linux kernel that has since come under active exploitation in the wild. The vulnerability was reported to Linux kernel maintainers
Source: Linux Kernel Dirty Frag LPE Exploit Enables Root Access Across Major Distributions via The Hacker News — published 08 May 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.