Dirty Frag [CVE Pending]

Incident Report for CloudLinux

Update

We are continuing to investigate this issue.
Posted May 07, 2026 - 21:48 UTC

Investigating

Dirty Frag [CVE Pending] is a Linux kernel local privilege escalation in the xfrm subsystem. The flaw lives in the ESP-in-UDP MSG_SPLICE_PAGES no-COW fast path and is reachable via the XFRM user netlink interface, which auto-loads the relevant modules. A working public proof-of-concept exists; any unprivileged local user can use it to gain root in a single command.

Affected Components:
CloudLinux 7h, 8, 9, and 10.

Published blog:
https://blog.cloudlinux.com/dirty-frag-mitigation-and-kernel-update
Posted May 07, 2026 - 21:47 UTC