NY01:02
    LDN06:02
    HKG13:02
    TYO14:02
    Gold4,510+0.25%
    Bitcoin76,681+1.66%
    Gold4,510+0.3%
    Bitcoin76,681+1.7%
    LATEST NEWS
    Secret Service Fatally Shoots Man After White House Checkpoint Gunfire37 minutesNational Gallery spotlights Impressionism with new presentation on the National Mallabout 4 hoursDPR posts citywide events calendar as summer programming begins across DCabout 4 hoursD.C. Parks and Recreation Publishes Updated Citywide Events Calendarabout 4 hoursDC.gov posts profile for Jeffrey Seltzer on Senior Leadership Teamabout 4 hoursDHCD publishes Open Government and FOIA guidance for District residents and requestersabout 4 hoursHow to Report a Partner’s Distributive Share on DC Combined Business Returnsabout 4 hoursDC DGS Schedules Community Meeting on Stoddert siteabout 4 hoursABCA posts '2027 LQ0' notice on DC.gov, signaling licensing activity across city neighborhoodsabout 4 hoursDC.gov's events calendar centralizes public programs and neighborhood happeningsabout 4 hours16th Street Heights, Carter Barron East Host Neighborhood Yard Sales on May 16about 4 hoursDHS events page lists public briefings and panels at its Washington, D.C. sitesabout 4 hoursDistrict updates official events calendar with city meetings, programs and cultural listingsabout 4 hoursDC’s Department of Employment Services emphasizes services on does.dc.gov portalabout 4 hoursDC Public Schools' events page centralizes districtwide programs and meetingsabout 4 hoursSecret Service Fatally Shoots Man After White House Checkpoint Gunfire37 minutesNational Gallery spotlights Impressionism with new presentation on the National Mallabout 4 hoursDPR posts citywide events calendar as summer programming begins across DCabout 4 hoursD.C. Parks and Recreation Publishes Updated Citywide Events Calendarabout 4 hoursDC.gov posts profile for Jeffrey Seltzer on Senior Leadership Teamabout 4 hoursDHCD publishes Open Government and FOIA guidance for District residents and requestersabout 4 hoursHow to Report a Partner’s Distributive Share on DC Combined Business Returnsabout 4 hoursDC DGS Schedules Community Meeting on Stoddert siteabout 4 hoursABCA posts '2027 LQ0' notice on DC.gov, signaling licensing activity across city neighborhoodsabout 4 hoursDC.gov's events calendar centralizes public programs and neighborhood happeningsabout 4 hours16th Street Heights, Carter Barron East Host Neighborhood Yard Sales on May 16about 4 hoursDHS events page lists public briefings and panels at its Washington, D.C. sitesabout 4 hoursDistrict updates official events calendar with city meetings, programs and cultural listingsabout 4 hoursDC’s Department of Employment Services emphasizes services on does.dc.gov portalabout 4 hoursDC Public Schools' events page centralizes districtwide programs and meetingsabout 4 hours
    Technology

    Linux “Dirty Frag” zero-day with PoC exploit enables root privilege escalation on major distributions

    A new Linux zero-day vulnerability, 'Dirty Frag,' enables local root privilege escalation across major distributions by chaining two kernel flaws.

    Published9 May 2026, 07:00:18
    Linux “Dirty Frag” zero-day with PoC exploit enables root privilege escalation on major distributions
    A360
    Key Takeaways✦ Atlas AI
    01

    A new Linux zero-day vulnerability, 'Dirty Frag,' allows local attackers to gain root privileges on major Linux distributions by chaining two kernel flaws, posing a significant security risk.

    02

    This critical privilege escalation vulnerability, present for nine years, affects widely used distributions like Ubuntu and Red Hat, highlighting a long-standing security oversight in the Linux kernel.

    03

    The premature public disclosure of 'Dirty Frag' and its proof-of-concept exploit before patches are available creates an immediate threat, necessitating urgent mitigation strategies like module removal despite potential service impacts.

    Atlas AI

    Atlas AI

    A newly disclosed Linux kernel zero-day vulnerability dubbed “Dirty Frag” can allow local attackers to escalate privileges to root on many widely used Linux distributions, according to documentation and a proof-of-concept (PoC) exploit released this week.

    Security researcher Hyunwoo Kim said the bug stems from a class of issues affecting the Linux kernel’s algif_aead cryptographic algorithm interface, and that it was introduced roughly nine years ago.

    How the exploit works

    Kim said “Dirty Frag” achieves privilege escalation by chaining two kernel page-cache write flaws — described as the “xfrm-ESP Page-Cache Write” issue and the “RxRPC Page-Cache Write” issue — to modify protected system files in memory without authorization.

    He said the technique is deterministic and does not rely on a race condition.

    Affected systems and patch status

    Kim said the issue affects major distributions including Ubuntu, Red Hat Enterprise Linux, CentOS Stream, AlmaLinux, openSUSE Tumbleweed, and Fedora.

    He also said an embargo on full public disclosure was broken on May 7, 2026, leading to the publication of documentation and a PoC exploit. At the time of disclosure, he said patches had not yet been released for affected systems.

    The two vulnerabilities chained by the exploit are tracked as:

    - CVE-2026-43284 for the xfrm-ESP issue - CVE-2026-43500 for the RxRPC issue

    Mitigation

    As a mitigation, Kim advised disabling the vulnerable kernel modules esp4, esp6, and rxrpc, noting that doing so may break IPsec VPN functionality and AFS distributed network file systems.

    Share

    Related Articles

    About this story

    Atlas360 covers Technology as part of a broader effort to give international readers fast, source-checked context on global affairs. Our newsroom monitors original reporting from wire services, accredited correspondents and verified eyewitness accounts, then re-summarises the most important facts in clear, plain-language English so that you can understand both what happened and why it matters.

    Every published article on Atlas360 is reviewed for accuracy, balance and timeliness before it reaches the homepage. When new information emerges — for example a correction from an official source, a casualty update, or a clarifying statement from a named spokesperson — we update the story in place and keep the original publication time so readers can track how a developing situation evolves.

    If you want to keep following Technology, you can browse the related coverage at the foot of this page, subscribe to the Atlas360 newsletter for a daily roundup, or open the relevant topic page where every story we have published on the subject is listed in reverse chronological order. Reader signals from the community feed also shape which threads we keep reporting on.

    Atlas360

    Sign up for Atlas Daily

    The daily global news briefing you can trust.

    every weekday·Read it now

    or
    Sign in

    Already subscribed? Sign in and we won't show you this message again.