Linux kernel exposed to DirtyClone (CVE-2026-43503), a high-risk local privilege escalation vulnerability with CVSS 8.8. Unprivileged users can gain
In late June 2026, the Linux kernel was exposed to a new local privilege escalation vulnerability named DirtyClone, with CVE identifier CVE-2026-43503. This vulnerability was discovered by the security research team of JFrog, a software supply chain platform provider, while auditing recent kernel patching status. JFrog notified Linux kernel maintainers on May 19 and merged the patch into the mainline version v7.1-rc5 on May 21. The CVSS 3.1 severity score for this vulnerability is 8.8, classifying it as a high-risk vulnerability. Any unprivileged local user can manipulate the Linux page cache (Page Cache) through this flaw to gain root access privileges. This vulnerability is an unresolved issue discovered after the DirtyFrag series of vulnerabilities (including CVE-2026-43284 and CVE-2026-43500), and attackers can exploit it via another packet processing path in the XFRM/IPsec subsystem[1][2].
The core mechanism of the DirtyClone vulnerability lies in the Linux kernel's failure to correctly propagate the SKBFL_SHARED_FRAG security marker when internally copying network packets. This causes leakage in the propagation of shared fragments (shared-frag), enabling attackers to corrupt the page cache of privileged binary files. The JFrog security team developed a proof-of-concept (PoC) for this vulnerability, named DirtyClone, to demonstrate a broader exploitation pattern that can affect buffers (socket buffer, skb) across multiple communication endpoints. The attack's underlying capability is not limited to a single vulnerable code path but involves packet processing paths within the XFRM/IPsec subsystem. Notably, this attack only rewrites the page cache in memory, not physical files on the filesystem, making traditional file integrity checks difficult to detect. This vulnerability requires CAP_NET_ADMIN privileges, which attackers can obtain by creating an unprivileged user namespace, thereby bypassing the attack prerequisite[1][2][3].
CVE-2026-43503 primarily affects mainstream distributions using unpatched Linux kernels, including Debian, Ubuntu, and Fedora. Any Linux kernel system that has not fully applied the DirtyFrag series (CVE-2026-43284 and CVE-2026-43500) patch chain is at risk. Particularly, mainline, stable, or Long Term Support (LTS) kernel branches that applied initial mitigations but lack subsequent follow-up patches may still be vulnerable to specific bypass attacks. Since the vulnerability involves only local privilege escalation, no remote attack vector (Remote Vector) has been discovered so far. In containerized environments, if namespace creation is not properly restricted, attackers may exploit this vulnerability to achieve container escape (Container Escape) and gain host root privileges[1][2][4].
For the DirtyClone vulnerability, JFrog recommends the permanent protection measure of immediately updating to a Linux kernel version containing the patch (such as v7.1-rc5 or backported versions from various distributions). If immediate patching is not possible, the following temporary protection measures can be taken: First, set the value of kernel.unprivileged_userns_clone to 0 to prevent attackers from obtaining CAP_NET_ADMIN privileges; second, blacklist Linux kernel modules such as esp4, esp6, and rxrpc to block in-place decryption primitives and prevent modification of page cache contents. JFrog warns that any system that has not fully applied the DirtyFrag series patch chain is at risk, and only after applying the complete series of patches can the system obtain full protection[1][2][4].