Filters
1158
456
234
167
156
78
43
38
37
35
33
28
28
26
23
22
21
19
19
16
16
16
16
12
11
11
11
11
11
10
10
9
8
7
7
6
6
6
6
5
5
5
5
5
4
4
4
4
3
3
3
3
3
3
3
3
3
3
3
3
3
2
2
2
2
2
2
2
2
2
2
2
2
2
2
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
0
0
0
0
602
575
395
391
315
304
189
128
127
125
122
120
97
82
77
69
57
48
10
1
1
1
Article

Two severe Linux vulnerabilities allow root access, with exploit code already circulating online

Ars Technica May 11, 2026

TL;DR

A vulnerability called 'Dirty Frag' lets low-privilege users, including those on virtual machines, gain full root control of Linux servers, with exploit code leaked online and working reliably across virtually all Linux distributions.

The exploit is deterministic (works the same way every time), leaves no crashes behind, and is therefore stealthy, making it harder for defenders to detect attacks in progress.

Microsoft has reported signs that hackers are already experimenting with Dirty Frag in the wild, and a second vulnerability called 'Copy Fail', disclosed the previous week with no patches yet available, shares the same dangerous characteristics.

Intelligence

For developers, engineers, and businesses running Linux-based servers or cloud infrastructure, including fintechs, SaaS platforms, and any team using shared hosting environments, this is an active threat requiring immediate attention, not a future concern.

The combination of a working public exploit, no available patch for Copy Fail, and confirmed attacker experimentation means the window for safe inaction is effectively closed right now. In the next 2 to 4 weeks, system administrators should audit all Linux environments for exposure, apply any patches as they are released, and restrict untrusted user access to shared servers as a stopgap.

Funding extracted from this article

0

No funding rounds were extracted from this article.

Regulatory activity extracted

0

No regulatory actions were extracted from this article.

Tenders extracted

0

No tenders were extracted from this article.

Further reading

More on the companies named in this article.

Companies named

1

People named

0

No people were extracted from this article.