Important Warning Regarding Your IT Security
Important Warning Regarding Your IT Security

Newsletter: Latest Linux Vulnerabilities

Copy Fail and Dirty Frag

Within a week, two serious security vulnerabilities in the Linux kernel were disclosed. Both allow an attacker with a standard user account to gain full administrative privileges on a Linux system. Nearly all major distributions released since 2017 are affected, including Ubuntu, Debian, RHEL, SUSE, Fedora, as well as Rocky and Alma Linux.

Copy Fail (CVE-2026-31431)

On April 29, 2026, the Xint Code research team disclosed the “Copy Fail” vulnerability. The complete attack fits into 732 bytes of code and has been verified in practice on current versions of Ubuntu, RHEL, SUSE, and Amazon Linux, among others.

Why this gap is particularly critical

Common kernel vulnerabilities are difficult to exploit in practice because they rely on narrow time windows or distribution-specific configurations. Copy Fail is not subject to these limitations. The attack is deterministic, meaning it works reliably and without any random factors.

Technically, the vulnerability manipulates the page cache—the area where the kernel temporarily stores file contents in memory. This allows the contents of a program running with administrator privileges to be altered. Two characteristics make this particularly problematic: No traces remain on the hard drive because only RAM is affected. And because the page cache is shared system-wide, a compromised container in cloud environments can take over the host and, consequently, other containers as well.

You need to take more immediate action when dealing with multi-user systems and jump hosts, container and Kubernetes platforms, build servers that automatically execute third-party code, and Linux servers running exposed web applications.

The first step is to install the kernel updates that have been available since early May. If this is not possible in the short term, the relevant kernel module can be disabled without affecting widely used components such as disk encryption, IPsec, SSH, or OpenSSL.

Dirty Frag (CVE-2026-43284 and CVE-2026-43500)

Just one week later, on May 8, 2026, the next vulnerability, “Dirty Frag,” was discovered. It also allows an attacker with local access—for example, via a compromised SSH account or a web shell—to gain full control over the system.
The threat situation here is significantly more serious: Microsoft is already observing active attack campaigns that use Dirty Frag after gaining initial access. This means that the vulnerability’s disclosure and its actual exploitation are occurring simultaneously.

The technology behind it

Dirty Frag joins the family of page-cache attacks, which already includes Dirty Pipe (2022) and Copy Fail. What makes it unique is the combination of two independent vulnerabilities in different kernel modules. As a result, the attack works even if individual protective measures against Copy Fail have already been implemented. Furthermore, the attack is reliable, causes no crashes, and thus leaves hardly any noticeable traces.

At first glance, a local privilege escalation may seem less dramatic than a vulnerability accessible from the internet. In reality, it is the missing link that turns a manageable incident into a total disaster. Only administrator privileges allow attackers to disable security tools, manipulate log files, extract access credentials, and establish a permanent foothold in the system. If personal data is being processed, this quickly results in a data breach subject to reporting under the GDPR, with the familiar 72-hour deadlines.

Until official kernel patches are available for all versions, you should not wait for the regular patch cycle. Four steps are recommended: Disable affected kernel modules unless they are required for operations. Check local access permissions and deactivate accounts that are no longer needed. Ensure container hardening with active security profiles. And expand monitoring to include indicators of unexpected privilege escalations.

In conclusion

What you should take away from both gaps

Copy Fail and Dirty Frag demonstrate that simply keeping systems up to date with the latest patches is no guarantee if the underlying vulnerability has been lurking unnoticed in the code for years. Vulnerabilities affecting the kernel itself cannot be mitigated by a single security product. The only effective solution is a combination of up-to-date patches, well-designed architecture, restrictive local access permissions, and monitoring that actually detects anomalies.

How we help

If you’re unsure how far an attacker could actually go in your environment, please feel free to contact us. We’ll help you assess the security vulnerabilities, implement countermeasures if necessary, and show you how to protect yourself from similar attacks in the future.

Would you like to receive more information about IT security?

Then why not get in touch with our experts?

csm nicolas roesener e35f74755d
Nikolas Rösener
Security Expert

Sign up for our "
" Cyber Security Newsletter

Our newsletter keeps you up to date on the most important topics in IT security.
The content is created and curated specifically for you by our cybersecurity experts.

You are currently viewing placeholder content from Mailjet. To view the actual content, click the button below. Please note that doing so will result in data being shared with third-party providers.

More Information