{"id":445709,"date":"2026-05-12T22:53:11","date_gmt":"2026-05-12T22:53:11","guid":{"rendered":"https:\/\/www.newsbeep.com\/ie\/445709\/"},"modified":"2026-05-12T22:53:11","modified_gmt":"2026-05-12T22:53:11","slug":"linux-defenders-face-patch-and-exploit-race","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ie\/445709\/","title":{"rendered":"Linux Defenders Face Patch and Exploit Race"},"content":{"rendered":"<p class=\"text-muted\">\n                                            <a href=\"https:\/\/www.bankinfosecurity.com\/security-operations-c-444\" id=\"asset_topic_1_1\" rel=\"nofollow noopener\" target=\"_blank\">Security Operations<\/a>\n                                                    <\/p>\n<p>                    Kernel Privilege Escalation Has One Linux Maintainer Contemplating a &#8216;Kill Switch&#8217;<\/p>\n<p>                                                <a class=\"author-link\" href=\"https:\/\/www.bankinfosecurity.com\/authors\/tiffany-wang-i-7880\" rel=\"nofollow noopener\" target=\"_blank\">Tiffany Wang<\/a>                                                     \u2022<br \/>\n                        May 12, 2026 \u00a0 \u00a0 <a href=\"https:\/\/www.bankinfosecurity.com\/linux-defenders-face-patch-exploit-race-a-31669#disqus_thread\" rel=\"nofollow noopener\" target=\"_blank\"><\/p>\n<p>                <img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/ie\/wp-content\/uploads\/2026\/05\/linux-defenders-face-patch-exploit-race-image_large-3-a-31669.jpg\" alt=\"Linux Defenders Face Patch and Exploit Race\" class=\"img-responsive \"\/><br \/>\n                Image: Shutterstock            <\/p>\n<p>Back-to-back kernel vulnerabilities in Linux has defenders scrambling to apply defenses in the age of quick turnaround time for hackers to exploit nascent flaws.<\/p>\n<p>See Also: <a href=\"https:\/\/www.bankinfosecurity.com\/how-organizations-are-strengthening-defenses-against-scattered-spider-a-31660?rf=RAM_SeeAlso\" rel=\"nofollow noopener\" target=\"_blank\">How Organizations Are Strengthening Defenses Against Scattered Spider<\/a><\/p>\n<p>&#8220;Dirty Frag&#8221; and &#8220;Copy Fail&#8221; kernel privilege escalation vulnerabilities became public knowledge within two weeks of each other (see: <a href=\"https:\/\/www.bankinfosecurity.com\/dirty-frag-gives-root-on-linux-distros-a-31641\" rel=\"nofollow noopener\" target=\"_blank\">&#8216;Dirty Frag&#8217; Gives Root on Linux Distros<\/a>).<\/p>\n<p>Microsoft <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/05\/08\/active-attack-dirty-frag-linux-vulnerability-expands-post-compromise-risk\/ \" target=\"_blank\" rel=\"nofollow noopener\">said<\/a> in a Friday blog that it has found limited in-the-wild activity associated with either one of the vulnerabilities. <\/p>\n<p>One Linux maintainer is floating the possibility of integrating a &#8220;kill switch&#8221; feature that would allow admins to temporarily shut down vulnerable kernel functions while patches are developed. <\/p>\n<p>&#8220;For most users, the cost of &#8216;this socket family stops working for the day&#8217; is much smaller than the cost of running a known vulnerable kernel until the fix land,&#8221; Linux stable kernel co-maintainer and Nvidia engineer Sasha Levin wrote in <a href=\" https:\/\/lore.kernel.org\/all\/20260507070547.2268452-1-sashal@kernel.org\/\" target=\"_blank\">an email<\/a>.<\/p>\n<p>The proposal is not official and it&#8217;s only meant to buy time between kernel vulnerability discoveries and patch releases.<\/p>\n<p>&#8220;As we&#8217;ve seen with the discovery of &#8216;Dirty Frag&#8217; fresh on the heels of &#8216;Copy Fail,&#8217; AI-assisted vulnerability discovery is rapidly accelerating the identification of new vulnerabilities, a trend that is only going to continue as these models continue to become more powerful,&#8221; said Scott Caveza, senior staff research engineer at Tenable.<\/p>\n<p>Defenders in production environments are wary about collateral damages of emergency kernel patching.<\/p>\n<p>&#8220;Applying kernel updates and rebooting across enterprise systems requires planning, downtime and risk assessments, leaving system administrators on edge for the &#8216;what if&#8217; scenarios: what happens if this patch causes unrelated performance issues?&#8221; Caveza said.<\/p>\n<p>&#8220;Dirty Frag&#8221; affects Linux distributions including Ubuntu, Red Hat Enterprise Linux, CentOS Stream, AlmaLinux, openSUSE Tumbleweed and Fedora. It chains two vulnerabilities together: one impacts modules that provide support for storage for EFI boot loaders and is tracked as <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-43284\" target=\"_blank\" rel=\"nofollow noopener\">CVE-2026-43284<\/a>.<\/p>\n<p>The other affects the RxRPC networking subsystem and was assigned <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-43500\" target=\"_blank\" rel=\"nofollow noopener\">CVE-2026-43500<\/a> on Monday.<\/p>\n<p>&#8220;A low-privileged local attacker can abuse zero-copy\/splice mechanisms to corrupt privileged files such as \/usr\/bin\/su or \/etc\/passwd and obtain root privileges, making the issue part of the same broader bug class as Dirty Pipe and Copy Fail,&#8221; <a href=\"https:\/\/access.redhat.com\/security\/cve\/cve-2026-43284\" target=\"_blank\" rel=\"nofollow noopener\">said<\/a> RedHat.<\/p>\n","protected":false},"excerpt":{"rendered":"Security Operations Kernel Privilege Escalation Has One Linux Maintainer Contemplating a &#8216;Kill Switch&#8217; Tiffany Wang \u2022 May 12,&hellip;\n","protected":false},"author":2,"featured_media":445710,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[14349,11571,14332,14335,14334,14333,14342,14343,14344,14345,14347,61,14336,14339,14341,14340,14338,14337,60,14348,12802,14346,80],"class_list":["post-445709","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-anti-money-laundering","tag-authentication","tag-bank-information-security","tag-bank-information-security-regulations","tag-bank-regulations","tag-banking-information-security","tag-fdic","tag-fincen","tag-gao","tag-glba","tag-identity-theft","tag-ie","tag-information-security","tag-information-security-articles","tag-information-security-events","tag-information-security-news","tag-information-security-webinars","tag-information-security-white-papers","tag-ireland","tag-phishing","tag-risk-management","tag-sarbanes-oxley-sox","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/445709","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/comments?post=445709"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/445709\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media\/445710"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media?parent=445709"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/categories?post=445709"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/tags?post=445709"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}