Linux Kernel Dirty Frag LPE Exploit Enables Root Access Across Major Distributions
A new, unpatched local privilege escalation (LPE) vulnerability affecting the Linux kernel has come to light.
It has been referred to as a replacement for Copy Fail (CVE-2026-31431, CVSS score: 7.8), a recently discovered LPE vulnerability affecting the Linux kernel that has subsequently been actively exploited in the field. On April 30, 2026, the Linux kernel maintainers were informed of the vulnerability.
According to a write-up by security researcher Hyunwoo Kim (@v4bel), Dirty Frag is a vulnerability (class) that obtains root privileges on the majority of Linux distributions by chaining the xfrm-ESP Page-Cache Write vulnerability and the RxRPC Page-Cache Write vulnerability.
The bug class that includes Dirty Pipe and Copy Fail is expanded by the case Dirty Frag. There is no n...

