CVE Tools

New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets

The Hacker NewsBy The Hacker News

PoC publicLinux Kernel

Our summary

A newly disclosed Linux kernel flaw in the DirtyFrag family, called DirtyClone, can allow a local attacker to corrupt file-backed memory via cloned packet handling and achieve root privileges. The issue is tracked as CVE-2026-43503 (CVSS 8.8) and matters because the demonstrated technique modifies in-memory data only—so file integrity tools may not detect it and a reboot restores the original binary. JFrog Security Research has shared a working exploit, and the fix has already landed upstream; unpatched systems should update their kernels promptly.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store