[Security Advisory] CVE-2026-43284, CVE-2026-43500: “DirtyFrag” Linux kernel local privilege escalation — mitigation required
Blog post from Nebius
Two Linux kernel vulnerabilities, CVE-2026-43284 and CVE-2026-43500, collectively referred to as "DirtyFrag," were disclosed on May 7, 2026, allowing a local unprivileged user to escalate to root without special privileges. These vulnerabilities are triggered by specific kernel modules, esp4/esp6 and rxrpc, which are used in IPsec (ESP) tunnels and AFS/Kerberos-based storage environments, respectively. While no exploitation evidence has been found against Nebius infrastructure, Nebius is actively working on a permanent solution and recommends immediate mitigations. For Compute instances, disabling the vulnerable modules can be done through a specific shell command, while Managed Kubernetes nodes require applying a DaemonSet with a provided YAML configuration to disable the modules. These actions aim to mitigate the risk until a permanent solution is available.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Kubernetes | 3 | 2,019 | 384 | 116 | -16% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.