Dirty Frag [CVE-2026-43284]

Incident Report for CloudLinux

Resolved

This incident has been resolved.
Posted May 27, 2026 - 18:04 UTC

Monitoring

A fix has been implemented and we are monitoring the results.
Posted May 22, 2026 - 10:07 UTC

Update

"DirtyDecrypt" proof-of-concept clarification:

A new proof-of-concept named "DirtyDecrypt" is circulating in the press, including a Bleeping Computer write-up.

Our team has reviewed the PoC and confirmed it does not work against systems that have applied a patched kernel from any of the three streams below. Customers who are already patched require no additional action.
Posted May 19, 2026 - 20:44 UTC

Update

Patched kernels are available in the AlmaLinux stable repository. Target versions:
CL9 / AlmaLinux 9: kernel-5.14.0-611.54.3.el9_7 or newer
CL10 / AlmaLinux 10: kernel-6.12.0-124.55.2.el10_1 or newer

Patched kernels for CL7h and CL8 are now available in the beta channel. Target versions:
CL7h: kernel-4.18.0-553.123.2.lve.el7h or newer
CL8: kernel-4.18.0-553.123.2.lve.el8 or newer
Posted May 08, 2026 - 18:22 UTC

Update

KernelCare patches are actively deploying. Rollout is in progress for the following distros (signed versions included):

- RHEL 8
- CloudLinux 8
- CloudLinux 7 Hybrid
- Oracle Linux 8
- CentOS 8
- Rocky Linux 8
- AlmaLinux 8

These should reach the main feed within the next couple of hours. Further updates to follow.
Posted May 08, 2026 - 11:43 UTC

Identified

Please refer to the mitigation and kernel update steps published in the blog:
https://blog.cloudlinux.com/dirty-frag-mitigation-and-kernel-update
Posted May 08, 2026 - 10:09 UTC

Update

We are continuing to investigate this issue.
Posted May 07, 2026 - 21:48 UTC

Investigating

Dirty Frag [CVE Pending] is a Linux kernel local privilege escalation in the xfrm subsystem. The flaw lives in the ESP-in-UDP MSG_SPLICE_PAGES no-COW fast path and is reachable via the XFRM user netlink interface, which auto-loads the relevant modules. A working public proof-of-concept exists; any unprivileged local user can use it to gain root in a single command.

Affected Components:
CloudLinux 7h, 8, 9, and 10.

Published blog:
https://blog.cloudlinux.com/dirty-frag-mitigation-and-kernel-update
Posted May 07, 2026 - 21:47 UTC
This incident affected: CloudLinux OS Components (CloudLinux Kernel).