Linux kernel maintainers security patch release for CVE-2026-43503
Security Patch Release
Summary
Hide ▲
Show ▼
Linux kernel merged and shipped the DirtyClone security fix for CVE-2026-43503, closing a CVSS 8.8 local privilege-escalation path that could let affected systems be rooted.
Related Happenings
Progress LoadMaster CVE-2026-8037 patch release
Security Patch Release
H score52
First: 30.06.2026 10:38
Last: 30.06.2026 10:38
Sources 1
About this happening:
Progress published fixed LoadMaster versions for CVE-2026-8037, closing a pre-auth root command execution path on appliances with the API enabled. Administrators r...
Progress LoadMaster CVE-2026-8037 patch release
Security Patch ReleaseAbout this happening: Progress published fixed LoadMaster versions for CVE-2026-8037, closing a pre-auth root command execution path on appliances with the API enabled. Administrators r...
Microsoft security patch release for CVE-2026-41091 and CVE-2026-45498
Security Patch Release
H score44
First: 21.05.2026 10:49
Last: 21.05.2026 10:49
Sources 1
About this happening:
Microsoft rolled out security updates for Defender and related malware protection components to address two zero-days: CVE-2026-41091 and CVE-2026-45498. The fixes cover affected...
Microsoft security patch release for CVE-2026-41091 and CVE-2026-45498
Security Patch ReleaseAbout this happening: Microsoft rolled out security updates for Defender and related malware protection components to address two zero-days: CVE-2026-41091 and CVE-2026-45498. The fixes cover affected...
Latest development: 21.05.2026 12:52
Microsoft released patches for Microsoft Defender Antimalware Platform version 4.18.26040.7 to address CVE-2026-41091, a link-following privilege-escalation flaw that can let an authorized attacker elevate privileges locally to System, and CVE-2026-45498, a denial-of-service flaw. Microsoft said both vulnerabilities were publicly disclosed and exploited in the wild as zero-days. CISA added both flaws to its Known Exploited Vulnerabilities (KEV) list and urged federal agencies to patch them by June 3.
Linux distros patch release for Fragnasia (CVE-2026-46300)
Security Patch Release
H score25
First: 14.05.2026 10:34
Last: 14.05.2026 10:34
Sources 1
About this happening:
Linux distros are rolling out patches for CVE-2026-46300, a high-severity kernel flaw that can let unprivileged local attackers gain root on vulnerable Linux systems....
Linux distros patch release for Fragnasia (CVE-2026-46300)
Security Patch ReleaseAbout this happening: Linux distros are rolling out patches for CVE-2026-46300, a high-severity kernel flaw that can let unprivileged local attackers gain root on vulnerable Linux systems....
Linux kernel Dirty Frag patch release (CVE-2026-43284, CVE-2026-43500)
Security Patch Release
H score32
First: 11.05.2026 17:30
Last: 11.05.2026 17:30
Sources 1
About this happening:
Major Linux distributions are rolling out fixes for Dirty Frag, the Linux kernel patch release that covers CVE-2026-43284 and CVE-2026-43500. The update matter...
Linux kernel Dirty Frag patch release (CVE-2026-43284, CVE-2026-43500)
Security Patch ReleaseAbout this happening: Major Linux distributions are rolling out fixes for Dirty Frag, the Linux kernel patch release that covers CVE-2026-43284 and CVE-2026-43500. The update matter...
CISA KEV action for CVE-2026-31431 and FCEB remediation
Public Sector Action
H score37
First: 03.05.2026 09:26
Last: 03.05.2026 09:26
Sources 1
About this happening:
CISA added CVE-2026-31431 to its KEV catalog, putting Federal Civilian Executive Branch (FCEB) agencies on notice to remediate an actively exploited Linux privilege-es...
CISA KEV action for CVE-2026-31431 and FCEB remediation
Public Sector ActionAbout this happening: CISA added CVE-2026-31431 to its KEV catalog, putting Federal Civilian Executive Branch (FCEB) agencies on notice to remediate an actively exploited Linux privilege-es...
Timeline
-
26.06.2026 14:51 1 articles · 19d ago
Hyunwoo Kim submits a broader frag-transfer patch for the Linux kernel
Technical Analysis UpdateHyunwoo Kim submits a broader multi-site patch covering several remaining frag-transfer helpers in the Linux kernel, extending the fix beyond the original DirtyFrag paths where the shared-frag bit could be lost.
Show sources
- New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets — thehackernews.com — 26.06.2026 14:51
-
26.06.2026 14:51 2 articles · 19d ago
Linux kernel maintainers merge the DirtyClone fix into mainline
Mitigation Patch UpdateLinux kernel maintainers merge the combined DirtyClone fix, closing additional frag-transfer helper paths where the shared-frag bit could be dropped and using commit 48f6a5356a33.
Show sources
- New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets — thehackernews.com — 26.06.2026 14:51
- New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets — thehackernews.com — 26.06.2026 14:51
-
26.06.2026 14:51 1 articles · 19d ago
Linux kernel maintainers assign CVE-2026-43503 to the DirtyClone fix
Technical Analysis UpdateLinux kernel maintainers assign CVE-2026-43503 to the merged DirtyClone fix, formalizing the privilege-escalation flaw tracked at CVSS 8.8.
Show sources
- New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets — thehackernews.com — 26.06.2026 14:51
-
26.06.2026 14:51 1 articles · 19d ago
Linux v7.1-rc5 ships the DirtyClone fix
Mitigation Patch UpdateLinux v7.1-rc5 includes the DirtyClone fix on May 24, making the upstream patch available for downstream stable and LTS backports.
Show sources
- New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets — thehackernews.com — 26.06.2026 14:51
-
25.06.2026 03:00 1 articles · 21d ago
JFrog Security Research publishes a DirtyClone exploit walkthrough
Initial DisclosureJFrog Security Research publishes a working exploit walkthrough for DirtyClone on June 25, showing a public path to root through a cloned network packet and a local privilege-escalation flaw in the Linux kernel.
Show sources
- New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets — thehackernews.com — 26.06.2026 14:51