Linux bitten by second severe vulnerability in as many weeks

TL;DR AI
2 min readKey summary
Researchers disclosed two severe Linux kernel privilege-escalation flaws in page-cache handling, tracked as CVE-2026-43284 and CVE-2026-43500.
The bugs affect IPsec and RxRPC code paths and can be chained to rewrite cached file data, enabling local attackers to gain root access.
The issue is similar in spirit to Dirty Pipe/Dirty Frag-style attacks and impacts servers, VMs, and other exposed Linux systems.
Major distributions and environments should patch urgently; mitigations and kernel updates are the primary defense.



