LPE vulnerability DirtyClone in Linux (CVE‑2026‑43503)

JFrog researchers have demonstrated a new variant of the DirtyFrag vulnerability family — DirtyClone (CVE‑2026‑43503). The flaw is related to processing network packets in the XFRM/IPsec subsystem and arises from improper separation of memory roles between the page cache, skb, and cryptographic buffers. As a result, a local user with the CAP_NET_ADMIN privilege can write to the kernel file cache and overwrite portions of binary files, including critical ones such as /usr/bin/su.
Linux kernels lacking the full patch set for DirtyFrag (CVE‑2026‑43284, CVE‑2026‑43500, CVE‑2026‑46300, CVE‑2026‑43503) are vulnerable, including Debian-, Ubuntu-, Fedora‑based, and other distributions when user namespaces are enabled. Exploitation enables privilege escalation to root while bypassing integrity controls and leaving no noticeable traces in system logs.
Vulnerabilities
8.8
CVE-2026-43284
7.8
CVE-2026-43500
8.8
CVE-2026-43503
7.8
CVE-2026-46300
Researchers
Sandipan Roy
Hyunwoo Kim
V4Bel
Vendors
Jfrog
Debian
Ubuntu
Fedora
Products
Cap_Net_Admin
Dirtyclone
Dirtyfrag
Linux
Page Cache
Skb
More