Two severe Linux vulnerabilities allow root access, with exploit code already circulating online

May 11, 2026 Ars Technica global 187 words

TL;DR

A vulnerability called 'Dirty Frag' lets low-privilege users, including those on virtual machines, gain full root control of Linux servers, with exploit code leaked online and working reliably across virtually all Linux distributions.

The exploit is deterministic (works the same way every time), leaves no crashes behind, and is therefore stealthy, making it harder for defenders to detect attacks in progress.

Microsoft has reported signs that hackers are already experimenting with Dirty Frag in the wild, and a second vulnerability called 'Copy Fail', disclosed the previous week with no patches yet available, shares the same dangerous characteristics.

Intelligence

For developers, engineers, and businesses running Linux-based servers or cloud infrastructure, including fintechs, SaaS platforms, and any team using shared hosting environments, this is an active threat requiring immediate attention, not a future concern.

The combination of a working public exploit, no available patch for Copy Fail, and confirmed attacker experimentation means the window for safe inaction is effectively closed right now. In the next 2 to 4 weeks, system administrators should audit all Linux environments for exposure, apply any patches as they are released, and restrict untrusted user access to shared servers as a stopgap.

One company or person in this story has a tracked profile.

Filed under:

Recommended reading

Picked for you by topic, popularity and relevance — not just the newest posts.