{"id":657714,"date":"2026-05-09T07:29:14","date_gmt":"2026-05-09T07:29:14","guid":{"rendered":"https:\/\/www.newsbeep.com\/ca\/657714\/"},"modified":"2026-05-09T07:29:14","modified_gmt":"2026-05-09T07:29:14","slug":"critical-new-linux-zero-day-goes-public-what-admins-need-to-do-now","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ca\/657714\/","title":{"rendered":"Critical New Linux Zero-Day Goes Public\u2014What Admins Need To Do Now"},"content":{"rendered":"<p><img decoding=\"async\" class=\" top-image\" src=\"https:\/\/www.newsbeep.com\/ca\/wp-content\/uploads\/2026\/05\/1778311754_904_0x0.jpg\" alt=\"Linux penguin with glasses holding a red megaphone.\" data-height=\"3190\" data-width=\"4833\" fetchpriority=\"high\" style=\"position:absolute;top:0\"\/><\/p>\n<p>Dirty Frag Linux zero-day confirmed.<\/p>\n<p>getty<\/p>\n<p>If you thought that Linux was somehow the safe and secure choice of operating system, you might want to think again. Hot on the heels of the Copy Fail access vulnerability that had remained hidden for 9 years comes news that a new zero-day, with no patch available and granting hackers root, has been confirmed. On Friday, May 8, 2026, the Dirty Frag vulnerability was publicly disclosed after a strict embargo tregarding the vulnerability was broken. As such, and with a proof of concept exploit known, it\u2019s now only a matter of time before threat actors use this in the wild to attack systems. Here\u2019s what we know about CVE-2026-43284 and the workaround you can employ to mitigate against attacks.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-1 link-embed--long-title\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/06\/microsoft-says-edge-password-security-vulnerability-is-by-design-is-it-time-to-switch-to-chrome\/\" target=\"_blank\" aria-label=\"Microsoft Says Edge Password Security Vulnerability Is \u2018By Design\u2019\u2014Is It Time To Switch To Chrome?\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/06\/microsoft-says-edge-password-security-vulnerability-is-by-design-is-it-time-to-switch-to-chrome\/\" rel=\"nofollow noopener\">ForbesMicrosoft Says Edge Password Security Vulnerability Is \u2018By Design\u2019\u2014Is It Time To Switch To Chrome?By Davey Winder<\/a>What We Know About CVE-2026-43284, The Linux Dirty Frag Zero-Day<\/p>\n<p>Why is it always a Friday? Just as security teams and end users alike look forward to the weekend, a security issue rears its ugly head, putting a stop to all that. With the major Linux distributions still rolling out patches for the Copy Fail vulnerability, which the U.S. Cybersecurity and Infrastructure Security Agency has confirmed is <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/03\/update-linux-now-as-9-year-old-root-hack-confirmed-cisa-warns-users\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/03\/update-linux-now-as-9-year-old-root-hack-confirmed-cisa-warns-users\/\" target=\"_self\" aria-label=\"now being exploited by attackers\" rel=\"nofollow noopener\">now being exploited by attackers<\/a>, comes news that an even worse issue is out there. Dirty Frag, officially now tracked by the <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/29\/11-million-critical-vulnerabilities-exposed---act-now\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/29\/11-million-critical-vulnerabilities-exposed---act-now\/\" target=\"_self\" aria-label=\"Common Vulnerabilities and Exposures\" rel=\"nofollow noopener\">Common Vulnerabilities and Exposures<\/a> database as CVE-2026-43284, has been confirmed and publicly disclosed, all before a patch is ready to roll.<\/p>\n<p>The reason for the May 8 public disclosure, according to the security researcher responsible, Hyunwoo Kim, was someone breaking the embargo that was in place. \u201cBecause the embargo has now been broken, no patches or CVEs exist for <br \/>these vulnerabilities,\u201d Kim said. After consulting with the Linux Distros Openwall maintainers, and at their request, Kim confirmed, \u201cI am publicly releasing this <a class=\"color-link\" href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2026\/05\/07\/8\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.openwall.com\/lists\/oss-security\/2026\/05\/07\/8\" aria-label=\"Dirty Frag document\">Dirty Frag document<\/a>.\u201d<\/p>\n<p>Amazingly, just like Copy Fail before it in terms of age, the Dirty Frag privilege escalation flaw has been present in the Linux kernel, specifically its algif_aead cryptographic algorithm interface, for around nine years. <\/p>\n<p>Also, like Copy Fail, Kim said, \u201cDirty Frag likewise allows immediate root privilege escalation on all major distributions, and it chains two separate vulnerabilities.\u201d<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-2 link-embed--long-title\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/08\/critical-new-google-security-update-127-chrome-security-vulnerabilities-confirmed\/\" target=\"_blank\" aria-label=\"Critical New Google Security Update\u2014127 Chrome Security Vulnerabilities Confirmed\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/08\/critical-new-google-security-update-127-chrome-security-vulnerabilities-confirmed\/\" rel=\"nofollow noopener\">ForbesCritical New Google Security Update\u2014127 Chrome Security Vulnerabilities ConfirmedBy Davey Winder<\/a>How To Mitigate The Linux Dirty Frag Attack Risk Before A Patch Arrives<\/p>\n<p>To mitigate <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/02\/ongoing-ransomware-attacks-exploit-linux-vulnerability-cisa-warns\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/02\/ongoing-ransomware-attacks-exploit-linux-vulnerability-cisa-warns\/\" target=\"_self\" aria-label=\"Linux attacks\" rel=\"nofollow noopener\">Linux attacks<\/a> now that the zero-day has been publicly disclosed, and before a patch is ready to roll out, users are advised by Kim to remove the modules in which the vulnerabilities occur as follows:<\/p>\n<p> sh -c &#8220;printf &#8216;install esp4 \/bin\/false\\ninstall esp6 \/bin\/false\\ninstall rxrpc \/bin\/false\\n&#8217; &gt; \/etc\/modprobe.d\/dirtyfrag.conf; rmmod esp4 esp6 rxrpc 2&gt;\/dev\/null; true&#8221;<\/p>\n<p>Dirty Frag has been tested as being applicable to the following Linux distribution versions:<\/p>\n<p>Ubuntu 24.04.4: 6.17.0-23-genericRHEL 10.1: 6.12.0-124.49.1.el10_1.x86_64openSUSE Tumbleweed: 7.0.2-1-defaultCentOS Stream 10: 6.12.0-224.el10.x86_64AlmaLinux 10: 6.12.0-124.52.3.el10_1.x86_64Fedora 44: 6.19.14-300.fc44.x86_64_<\/p>\n<p>You can read more technical details and keep up to date with developments related to the latest Linux kernel zero-day at the official <a class=\"color-link\" href=\"https:\/\/github.com\/V4bel\/dirtyfrag\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/github.com\/V4bel\/dirtyfrag\" aria-label=\"Dirty Frag information site\">Dirty Frag information site<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"Dirty Frag Linux zero-day confirmed. getty If you thought that Linux was somehow the safe and secure choice&hellip;\n","protected":false},"author":2,"featured_media":657715,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[49,48,243437,243435,243432,243433,243436,243439,243438,243434,61],"class_list":["post-657714","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-ca","tag-canada","tag-copy-fail","tag-cve-2026-43284","tag-dirty-frag","tag-get-root","tag-hyunwoo-kim","tag-linux-security-warning","tag-linux-zero-day-gets-root-and-no-patch-ready","tag-no-patch-for-linux-zero-day","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/657714","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/comments?post=657714"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/657714\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media\/657715"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media?parent=657714"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/categories?post=657714"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/tags?post=657714"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}