New Linux kernel privilege escalation with no patch available
Information has been published on a new Linux kernel vulnerability allowing local privilege escalation. It resembles CVE-2026-31431, known as copy fail, from the previous week, and has been nicknamed dirty frag. No CVE number has been assigned yet. Working proof-of-concept code exists, but no exploitation in the wild is known. Every version since 2017 is affected and no patch is available. Distribution and vendor sites are the place to follow for mitigations and forthcoming fixes.
What this means for your organisation
Local privilege escalation requires the attacker to already have a foothold, and that is precisely why it matters: it turns a limited compromise into full control of the server. Environments where several users or customers share a kernel, such as container platforms and shared development servers, are particularly exposed. With working exploit code and no patch, interim measures have to be about limiting who gets to run code on the machine at all.
Berigo recommends
- Map which Linux systems let multiple users or workloads run code on the same kernel, and prioritise those.
- Track the security advisories from the distribution you run, and have a plan for rapid rollout once a fix lands.
- Tighten who holds shell access to production servers and remove accounts that do not need it.
- Increase monitoring for unexpected privilege changes and process launches on the most exposed systems.
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch