[Security Advisory] CVE-2026-43284, CVE-2026-43500: “DirtyFrag” Linux kernel local privilege escalation — mitigation required
Blog post from Nebius
Two Linux kernel vulnerabilities, CVE-2026-43284 and CVE-2026-43500, collectively referred to as "DirtyFrag," were disclosed on May 7, 2026, allowing a local unprivileged user to escalate to root without special privileges. These vulnerabilities are triggered by specific kernel modules, esp4/esp6 and rxrpc, which are used in IPsec (ESP) tunnels and AFS/Kerberos-based storage environments, respectively. While no exploitation evidence has been found against Nebius infrastructure, Nebius is actively working on a permanent solution and recommends immediate mitigations. For Compute instances, disabling the vulnerable modules can be done through a specific shell command, while Managed Kubernetes nodes require applying a DaemonSet with a provided YAML configuration to disable the modules. These actions aim to mitigate the risk until a permanent solution is available.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.