LPE vulnerability DirtyClone in Linux (CVE‑2026‑43503)
Attack Techniques & Methods2026-07-01, 10:17
JFrog researchers have demonstrated a new variant of the DirtyFrag vulnerability family — DirtyClone (CVE‑2026‑43503). The flaw is related to processing network packets in the
XFRM/IPsec subsystem and arises from improper separation of memory roles between the page cache, skb, and cryptographic buffers. As a result, a local user with the CAP_NET_ADMIN privilege can write to the kernel file cache and overwrite portions of binary files, including critical ones such as /usr/bin/su.Linux kernels lacking the full patch set for DirtyFrag (CVE‑2026‑43284, CVE‑2026‑43500, CVE‑2026‑46300, CVE‑2026‑43503) are vulnerable, including Debian-, Ubuntu-, Fedora‑based, and other distributions when
user namespaces are enabled. Exploitation enables privilege escalation to root while bypassing integrity controls and leaving no noticeable traces in system logs.Vulnerabilities
Researchers
Vendors
Products
More