Home / Companies / Nebius / Blog / Post Details
Content Deep Dive

[Security Advisory] CVE-2026-43284, CVE-2026-43500: “DirtyFrag” Linux kernel local privilege escalation — mitigation required

Blog post from Nebius

Post Details
Company
Date Published
Author
Nebius team
Word Count
290
Company Posts That Month
7
Language
English
Hacker News Points
-
Post removed?
No
Summary

Two Linux kernel vulnerabilities, CVE-2026-43284 and CVE-2026-43500, collectively referred to as "DirtyFrag," were disclosed on May 7, 2026, allowing a local unprivileged user to escalate to root without special privileges. These vulnerabilities are triggered by specific kernel modules, esp4/esp6 and rxrpc, which are used in IPsec (ESP) tunnels and AFS/Kerberos-based storage environments, respectively. While no exploitation evidence has been found against Nebius infrastructure, Nebius is actively working on a permanent solution and recommends immediate mitigations. For Compute instances, disabling the vulnerable modules can be done through a specific shell command, while Managed Kubernetes nodes require applying a DaemonSet with a provided YAML configuration to disable the modules. These actions aim to mitigate the risk until a permanent solution is available.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.