CVE-2026-43503Disclosure(linux / linux_kernel)

CRITICALCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 20 mentions and remains active

Immediate actions

  • Patch linux linux_kernel systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker through frag-transfer helpers Two frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail to propagate the SKBFL_SHARED_FRAG bit in skb_shinfo()->flags when moving frags from source to destination. __pskb_copy_fclone() defers the rest of the shinfo metadata to skb_copy_header() after copying frag descriptors, but that helper only carries over gso_{size,segs, type} and never touches skb_shinfo()->flags; skb_shift() moves frag descriptors directly and leaves flags untouched. As a result, the destination skb keeps a reference to the same externally-owned or page-cache-backed pages while reporting skb_has_shared_frag() as false. The mismatch is harmful in any in-place writer that uses skb_has_shared_frag() to decide whether shared pages must be detoured through skb_cow_data(). ESP input is one such writer (esp4.c, esp6.c), and a single nft 'dup to <local>' rule -- or any other nf_dup_ipv4() / xt_TEE caller -- is enough to land a pskb_copy()'d skb in esp_input() with the marker stripped, letting an unprivileged user write into the page cache of a root-owned read-only file via authencesn-ESN stray writes. Set SKBFL_SHARED_FRAG on the destination whenever frag descriptors were actually moved from the source. skb_copy() and skb_copy_expand() share skb_copy_header() too but linearize all paged data into freshly allocated head storage and emerge with nr_frags == 0, so skb_has_shared_frag() returns false on its own; they need no change. The same omission exists in skb_gro_receive() and skb_gro_receive_list(). The former moves the incoming skb's frag descriptors into the accumulator's last sub-skb via two paths (a direct frag-move loop and the head_frag + memcpy path); the latter chains the incoming skb whole onto p's frag_list. Downstream skb_segment() reads only skb_shinfo(p)->flags, and skb_segment_list() reuses each sub-skb's shinfo as the nskb -- both p and lp must carry the marker. The same omission also exists in tcp_clone_payload(), which builds an MTU probe skb by moving frag descriptors from skbs on sk_write_queue into a freshly allocated nskb. The helper falls into the same family and warrants the same fix for consistency; no TCP TX-side in-place writer is currently known to reach a user page through this gap, but a future consumer depending on the marker would regress silently. The same omission exists in skb_segment(): the per-iteration flag merge takes only head_skb's flag, and the inner switch that rebinds frag_skb to list_skb on head_skb-frags exhaustion does not fold the new frag_skb's flag into nskb. Fold frag_skb's flag at both sites so segments drawing frags from frag_list members carry the marker.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-664

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Active exploitation appears in 7 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 111 mentions across 31 observed days

What's happening

  • Active exploitation reported across 7 signals
  • Exploit tool or code specified in 22 signals
  • PoC mentioned or linked in 43 signals
  • Patch or workaround mentioned in 34 signals
  • Technical details provided in 91 signals
  • Disclosure: 45 classified signals
  • Peaked 24d ago at 20 mentions (2026-06-26); latest day: 1
  • 111 total mentions across 31 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline111 mentions / 31d
05101520Mentions · 2026-05-23: 1Mentions · 2026-05-24: 1Mentions · 2026-06-05: 1Mentions · 2026-06-06: 1Mentions · 2026-06-08: 1Mentions · 2026-06-25: 2Mentions · 2026-06-26: 20Mentions · 2026-06-27: 19Mentions · 2026-06-28: 6Mentions · 2026-06-29: 13Mentions · 2026-06-30: 5Mentions · 2026-07-01: 10Mentions · 2026-07-02: 2Mentions · 2026-07-03: 2Mentions · 2026-07-04: 3Mentions · 2026-07-05: 1Mentions · 2026-07-06: 2Mentions · 2026-07-07: 3Mentions · 2026-07-09: 1Mentions · 2026-07-14: 1Mentions · 2026-07-17: 4Mentions · 2026-07-18: 3Mentions · 2026-07-19: 1Mentions · 2026-07-22: 1Mentions · 2026-07-29: 1Mentions · 2026-08-03: 1Mentions · 2026-08-04: 1Mentions · 2026-09-06: 1Mentions · 2026-09-11: 1Mentions · 2026-09-19: 1Mentions · 2026-09-23: 1PoC Mentioned / Linked · 2026-06-25: 2PoC Mentioned / Linked · 2026-06-26: 5PoC Mentioned / Linked · 2026-06-27: 9PoC Mentioned / Linked · 2026-06-28: 2PoC Mentioned / Linked · 2026-06-29: 2PoC Mentioned / Linked · 2026-06-30: 4PoC Mentioned / Linked · 2026-07-01: 4PoC Mentioned / Linked · 2026-07-02: 2PoC Mentioned / Linked · 2026-07-06: 1PoC Mentioned / Linked · 2026-07-07: 1PoC Mentioned / Linked · 2026-07-17: 4PoC Mentioned / Linked · 2026-07-22: 1PoC Mentioned / Linked · 2026-07-29: 1PoC Mentioned / Linked · 2026-08-03: 1PoC Mentioned / Linked · 2026-08-04: 1PoC Mentioned / Linked · 2026-09-11: 1PoC Mentioned / Linked · 2026-09-19: 1PoC Mentioned / Linked · 2026-09-23: 1Exploit Tool / Code · 2026-06-25: 1Exploit Tool / Code · 2026-06-26: 4Exploit Tool / Code · 2026-06-27: 5Exploit Tool / Code · 2026-06-29: 1Exploit Tool / Code · 2026-06-30: 3Exploit Tool / Code · 2026-07-01: 1Exploit Tool / Code · 2026-07-02: 2Exploit Tool / Code · 2026-07-06: 1Exploit Tool / Code · 2026-07-17: 1Exploit Tool / Code · 2026-07-29: 1Exploit Tool / Code · 2026-08-03: 1Exploit Tool / Code · 2026-09-23: 1Active Exploitation · 2026-05-24: 1Active Exploitation · 2026-06-26: 1Active Exploitation · 2026-06-27: 2Active Exploitation · 2026-06-28: 1Active Exploitation · 2026-06-29: 2Patch / Workaround · 2026-06-05: 1Patch / Workaround · 2026-06-06: 1Patch / Workaround · 2026-06-08: 1Patch / Workaround · 2026-06-25: 1Patch / Workaround · 2026-06-26: 5Patch / Workaround · 2026-06-27: 6Patch / Workaround · 2026-06-28: 2Patch / Workaround · 2026-06-29: 5Patch / Workaround · 2026-06-30: 2Patch / Workaround · 2026-07-01: 5Patch / Workaround · 2026-07-02: 1Patch / Workaround · 2026-07-04: 1Patch / Workaround · 2026-07-07: 1Patch / Workaround · 2026-07-14: 1Patch / Workaround · 2026-07-17: 1Technical Details · 2026-06-05: 1Technical Details · 2026-06-06: 1Technical Details · 2026-06-08: 1Technical Details · 2026-06-25: 2Technical Details · 2026-06-26: 15Technical Details · 2026-06-27: 15Technical Details · 2026-06-28: 5Technical Details · 2026-06-29: 13Technical Details · 2026-06-30: 4Technical Details · 2026-07-01: 7Technical Details · 2026-07-02: 2Technical Details · 2026-07-03: 2Technical Details · 2026-07-04: 3Technical Details · 2026-07-05: 1Technical Details · 2026-07-06: 1Technical Details · 2026-07-07: 2Technical Details · 2026-07-09: 1Technical Details · 2026-07-14: 1Technical Details · 2026-07-17: 4Technical Details · 2026-07-18: 3Technical Details · 2026-07-22: 1Technical Details · 2026-07-29: 1Technical Details · 2026-08-03: 1Technical Details · 2026-08-04: 1Technical Details · 2026-09-11: 1Technical Details · 2026-09-19: 1Technical Details · 2026-09-23: 105-2306-0606-2606-2907-0207-0507-0907-1807-2909-0609-23
Signal classification6 categories
Disclosure
4540.5%
PoC
3027.0%
Patch
1311.7%
General
119.9%
Active Exploitation
65.4%
Exploit
65.4%
Referenced assets78 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-231
General1
2026-05-241
Active Exploitation1
2026-06-051
Patch1
2026-06-061
Patch1
2026-06-081
Patch1
2026-06-252
PoC2
2026-06-2620
Active Exploitation1Disclosure9Exploit1General4Patch1PoC4
2026-06-2719
Active Exploitation1Disclosure8Exploit2General2Patch3PoC3
2026-06-286
Active Exploitation1Disclosure3Patch1PoC1
2026-06-2913
Active Exploitation2Disclosure9Patch1PoC1
2026-06-305
Patch1PoC4
2026-07-0110
Disclosure3General1Patch2PoC4
2026-07-022
Exploit1PoC1
2026-07-032
Disclosure2
2026-07-043
Disclosure3
2026-07-051
Disclosure1
2026-07-062
Disclosure1Exploit1
2026-07-073
Disclosure2PoC1
2026-07-091
Disclosure1
2026-07-141
Patch1
2026-07-174
PoC4
2026-07-183
Disclosure2General1
2026-07-191
General1
2026-07-221
PoC1
2026-07-291
PoC1
2026-08-031
PoC1
2026-08-041
PoC1
2026-09-061
General1
2026-09-111
Disclosure1
2026-09-191
PoC1
2026-09-231
Exploit1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Disclosure

    🛑 A new #Linux kernel flaw lets a local user rewrite /usr/bin/su in memory and gain #root. The file on disk never changes. No audit trail. DirtyClone (CVE-2026-43503) is the fourth bug with this failure mode in two months. Details and what to do ↓ https://thehackernews.com/2026/06/new-dirtyclone-linux-kernel-flaw-lets.html

    Post summary

    A local privilege‑escalation flaw in the Linux kernel (CVE‑2026‑43503) lets a user overwrite /usr/bin/su in memory and achieve root without altering the file on disk.

    8102742118444.6K
    2.2M followersView on X
  • portbuster@portbuster1337
    Exploit

    Added 4 new LPE exploits to lpe-toolkit: - PEdit COW CVE-2026-46331 - DirtyClone CVE-2026-43503 - Bad Epoll CVE-2026-46242 - FUSE OOB CVE-2026-31694 https://github.com/portbuster1337/lpe-toolkit

    Post summary

    The post announces that four CVE-2026 local privilege escalation exploits have been added to the lpe-toolkit GitHub repository, providing users with immediate PoC and exploit code.

    465129519715.8K
    289 followersView on X
  • JFrog Security@JFrogSecurity
    PoC

    🚨 Successful PoC for Linux Kernel CVE-2026-43503 (DirtyFrag variant) 🚨 JFrog researchers successfully developed a privilege escalation exploit for CVE-2026-43503, a newly discovered DirtyFrag variant we dubbed "DirtyClone". The vulnerability was patched and merged into mainline Linux on May 21 (v7.1-rc5, commit 9e171fc1d7d7). Make sure your systems are up to date. Read the full technical writeup: https://research.jfrog.com/post/dissecting-and-exploiting-linux-lpe-variant-dirtyclone-cve-2026-43503/

    Post summary

    Researchers demonstrated a successful PoC for CVE-2026-43503, illustrating privilege escalation, while the kernel patch has already been merged and a detailed writeup is available.

    76712159424.8K
    5.5K followersView on X
  • Dark Web Informer@DarkWebInformer
    PoC

    ‼️ CVE-2026-43503: Python PoC for DirtyClone, a Linux kernel LPE via page-cache corruption exploit GitHub: https://github.com/entra1337/DirtyClone https://t.co/3O2hh9fSiN

    Post summary

    The tweet announces a Python Proof of Concept for CVE‑2026‑43503, a Linux kernel privilege‑escape vulnerability caused by page‑cache corruption, with a GitHub link to the code. No patch, active exploitation, or debunking is reported.

    235019210821.2K
    231.8K followersView on X
  • NullSecurityX@NullSecurityX
    PoC

    Dissecting and Exploiting Linux LPE Variant: DirtyClone (CVE-2026-43503) https://research.jfrog.com/post/dissecting-and-exploiting-linux-lpe-variant-dirtyclone-cve-2026-43503 https://t.co/GxRIdM8QWD

    Post summary

    The post links to research dissecting and providing a proof‑of‑concept for the DirtyClone Linux LPE vulnerability (CVE-2026-43503), with no indications of active exploitation, patches, or false‑positive status.

    4280139819.7K
    12.3K followersView on X
  • Cyber Security News@The_Cyber_News
    Disclosure

    New DirtyClone Linux Vulnerability Allows Attackers to Gain Root Access Via Cloned Packets Source: https://cybersecuritynews.com/dirtyclone-linux-vulnerability/ A new Linux kernel local privilege escalation vulnerability, dubbed “DirtyClone” (CVE-2026-43503), that allows unprivileged local users to gain full root access by manipulating cloned network packets through the XFRM/IPsec subsystem, all without leaving a trace in kernel logs or audit records. DirtyClone is a high-severity variant in the DirtyFrag vulnerability family, a class of Linux kernel memory corruption bugs affecting how socket buffers (skb) reference shared page-cache memory. #cybersecuritynews

    Post summary

    The article announces the discovery of a new Linux kernel local privilege escalation flaw (CVE‑2026‑43503) and outlines its technical details but provides no PoC, exploit code, or evidence of active exploitation.

    6352153429.7K
    70.7K followersView on X
  • portbuster@portbuster1337
    Exploit

    lpe-toolkit has been updated with new LPE exploits! New exploits added: - RefluXFS CVE-2026-64600 - CrackArmor CVE-2026-23268 - skb_shift CVE-2026-43503 - GRO Flag Loss CVE-2026-43503 - snap-confine CVE-2026-8933 https://github.com/portbuster1337/lpe-toolkit/releases/tag/v1.4.0

    Post summary

    The text announces an update to 'lpe-toolkit' with new local privilege escalation exploits for several CVEs and provides a direct link to the tool's release, making exploit availability the main takeaway.

    0230111668.5K
    366 followersView on X
  • MigawariIV@strinsert1Na
    Exploit

    もう当たり前のように PoC 出てくるのすごいね Dissecting and Exploiting Linux LPE Variant: DirtyClone (CVE-2026-43503) https://research.jfrog.com/post/dissecting-and-exploiting-linux-lpe-variant-dirtyclone-cve-2026-43503/

    Post summary

    The post announces that a PoC and functional exploit for CVE‑2026‑43503 (DirtyClone LPE) has been published, with technical details but no evidence of active exploitation or patches.

    0170945211.8K
    5.1K followersView on X
  • Tails@Tails_live
    Patch

    Tails 7.9.1 is out: https://tails.net/news/version_7.9.1/ It fixes CVE-2026-43503 (*DirtyClone*) and CVE-2026-46331 (*PACKET_EDIT_MEME*).

    Post summary

    Tails released version 7.9.1, which includes patches for CVE-2026-43503 (*DirtyClone*) and CVE-2026-46331 (*PACKET_EDIT_MEME*).

    3242104106.9K
    77.5K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-43503: Linux kernel: Analysis of the "DirtyClone" LPE (Dirty Frag family variant) https://www.openwall.com/lists/oss-security/2026/07/02/1 Dirty Frag, Fragnesia, DirtyClone trick the kernel into treating read-only, file-backed page cache memory as writable network buffers https://x.com/JFrogSecurity/status/2070144533648589079

    Post summary

    The article discusses the DirtyClone local privilege‑escapefault in Linux kernels, explaining how the flaw manipulates read‑only memory to gain elevated privileges, but it does not share a PoC, exploit code, patch, or evidence of active exploitation.

    011067358.7K
    4.7K followersView on X
  • Daily CyberSecurity@the_yellow_fall
    Disclosure

    DirtyClone (CVE-2026-43503) is a Linux kernel privilege escalation flaw rated CVSS 8.8. It abuses the page cache to turn a local user into root. #DirtyClone #LinuxKernel #PrivilegeEscalation #CVE202643503 #DirtyFrag https://securityonline.info/dirtyclone-linux-kernel-lpe https://t.co/t3qmIh7q6E

    Post summary

    DirtyClone (CVE-2026-43503) is a Linux kernel privilege escalation flaw rated CVSS 8.8 that abuses the page cache to elevate a local user to root, with details announced via a security article.

    217171174.5K
    12.9K followersView on X
  • Sekurak@Sekurak
    Disclosure

    🚨 Uwaga: Kolejna groźna podatność typu LPE w jądrze Linuksa (CVE-2026-43503) 💻 Choć jeszcze nie opadł kurz po podatnościach Copy Fail oraz Dirty Frag, a tymczasem pojawia się nowe zagrożenie Dirty Clone. 🛠️ Luka pozwala na uzyskanie uprawnień roota w większości współczesnych dystrybucji Linuksa. 🕵️‍♂️ Błąd polega na możliwości nieuprawnionej modyfikacji zawartości pamięci podręcznej stron (page cache) dla plików systemowych, co w efekcie umożliwia wstrzyknięcie i wykonanie dowolnego kodu. 🔥 Winowajcą okazały się w tym przypadku funkcje klonujące pakiety: __pskb_copy_fclone oraz skb_shift. 🛡️ Na szczęście oficjalne łatki bezpieczeństwa zostały wydane. Zalecamy niezwłoczną aktualizację. 👉 Szczegóły: https://sekurak.pl/dirty-clone-kolejny-sposob-na-roota-pod-linuksem/

    Post summary

    A new Linux kernel LPE vulnerability (CVE-2026-43503) has been disclosed; official patches are available and users are urged to apply them immediately.

    512040167.7K
    44.5K followersView on X
  • IT-Connect.fr@ITConnect_fr
    Disclosure

    DirtyClone (CVE-2026-43503) : un user local devient root sur Linux sans rien écrire sur le disque ni dans les logs. Debian, Ubuntu, Fedora touchés. Et patcher DirtyFrag ne suffit pas : il faut patch toute la chaîne. 👇 https://www.it-connect.fr/dirtyclone-la-faille-linux-qui-donne-un-acces-root-en-silence/ #linux #cybersecurite https://t.co/bmz4TA4dsb

    Post summary

    The article announces the DirtyClone CVE‑2026‑43503 flaw that allows local users to gain silent root access on multiple Linux distributions, highlighting that patches beyond DirtyFrag are required.

    01111961.9K
    11.6K followersView on X
  • Brad Spengler@spendergrsec
    General

    Anyway, totally unrelated, was just thinking about the current CVE system where you have exploits coming out weeks before a CVE number or description: https://lore.kernel.org/linux-cve-announce/2026052311-CVE-2026-46300-27bc@gregkh/T/#u https://lore.kernel.org/linux-cve-announce/2026052309-CVE-2026-43503-b134@gregkh/T/#u

    Post summary

    The text simply notes that exploits appear before CVE numbers, but provides no PoC, exploit code, active exploitation claims, patches, technical details, or debunking information.

    10126948.2K
    7.0K followersView on X
  • Linuxiac@linuxiac
    Patch

    Canonical says Ubuntu kernel updates are available for DirtyClone, a high-severity Linux local privilege escalation flaw tracked as CVE-2026-43503. https://linuxiac.com/canonical-confirms-ubuntu-fixes-for-dirtyclone-linux-kernel-flaw/ #Linux #Ubuntu #Security

    Post summary

    Canonical has released kernel updates to address the high‑severity local privilege escalation flaw CVE‑2026‑43503 for Ubuntu users.

    0203011.3K
    10.9K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    ثغرة جديده في نواه Linux اسمها DirtyClone تصعد صلاحيات المستخدم الى root بدون تعديل على الملفات. رقم الثغرة CVE-2026-43503 بتقييم 8.8 المزعج في DirtyClone أن التعديل يصير داخل الذاكرة فقط. يعني أدوات File Integrity التقليدية ماتساعد في هالحالة. https://t.co/e8JpnHjx0O

    Post summary

    The tweet announces a new Linux privilege‑escalation flaw, CVE‑2026‑43503 (score 8.8), named DirtyClone, which allows users to gain root by changing only memory, rendering traditional file‑integrity tools ineffective.

    23013103.7K
    50.1K followersView on X
  • dbugs@ptdbugs
    Active Exploitation

    Linux Kernel — net/skbuff: shared-frag marker not propagated through frag-transfer helpers (DirtyClone) CVE: CVE-2026-43503 PT ID: PT-2026-42878 Vendor: Linux Product: Linux Kernel (net/skbuff, XFRM/IPsec) CVSS: 8.8 Credits: JFrog Security Research Description: A local privilege escalation issue exists in the Linux networking stack due to the improper propagation of the SKBFL SHARED FRAG flag during fragment transfers. Several helpers and functions, including pskb copy fclone(), skb shift(), skb gro receive(), skb gro receive list(), tcp clone payload(), skb segment(), and skb try coalesce(), fail to carry over this marker when moving fragment descriptors. This creates a mismatch where a socket buffer (skb) may reference externally-owned or page-cache-backed pages while reporting that it does not have shared fragments via skb has shared frag(). This flaw can be exploited by in-place writers, such as ESP input (esp4.c, esp6.c), which rely on skb has shared frag() to determine if data must be processed through skb cow data(). An unprivileged user can leverage this to write into the page cache of a root-owned read-only file. Real-world exploitation, dubbed DirtyClone, allows an application to escalate privileges to administrator/root levels. References: • [https://dbugs.ptsecurity.com/vulnerability/CVE-2026-43503 ](https://dbugs.ptsecurity.com/vulnerability/CVE-2025-5777)• https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=48f6a5356a33dd78e7144ae1faef95ffc990aae0 -> (https://dbugs.ptsecurity.com/vulnerability/CVE-2025-5777)[ ](https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX693420)• [https://research.jfrog.com/post/dissecting-and-exploiting-linux-lpe-variant-dirtyclone-cve-2026-43503/ ](https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX693420) PoC/Exploit: https://github.com/rafaeldtinoco/security #dbugs_vuln

    Post summary

    CVE‑2026‑43503 is a local privilege escalation flaw in the Linux kernel that is actively exploited in the wild as DirtyClone, with PoC code publicly available and detailed technical information provided, but no patch or mitigation has yet been announced.

    0501161.1K
    3.0K followersView on X
  • ARI-4N@Agent15A
    Disclosure

    توجهتون رو به CVE-2026-43503 جلب میکنم، این آسیب پذیری به اسم DirtyClone که مکانیزم‌های محافظتی Copy-on-Write رو دور بزنه و میتونه منجر به LPE بشه. اطلاعات بیشتر

    Post summary

    The post announces CVE‑2026‑43503, called DirtyClone, noting that it bypasses Copy‑on‑Write protection and may lead to local privilege escalation.

    100162861
    705 followersView on X
  • Red Secure Tech Ltd.@redsecuretech
    Disclosure

    DirtyClone is a new Linux kernel privilege escalation flaw (CVE-2026-43503). It exploits cloned network packets to corrupt file-backed memory and grant root access. For More: https://www.redsecuretech.co.uk/blog/post/dirtyclone-linux-kernel-privilege-escalation-exploit/1277 #DirtyClone #CVE #PrivilegeEscalation #DirtyFrag #CyberSecurity #Linux #InfoSec https://t.co/f5PgISOD5N

    Post summary

    The post discloses DirtyClone as a Linux kernel privilege escalation flaw that corrupts file‑backed memory via cloned packets, granting root, but offers no PoC, exploit code, active‑exploitation evidence, or patch information.

    020107841
    76 followersView on X
  • Azubuike Ibe@ai_dev_official
    Disclosure

    A new Linux kernel vulnerability just dropped. CVE-2026-43503. Researchers are calling it DirtyClone. It is a local privilege escalation. An attacker with a low-privileged foothold on the system can escalate to root by exploiting a regression in packet cloning inside the networking stack, specifically a path through the netfilter TEE clone target. Mature code. Subtle regression. Root access. This is not remotely exploitable on its own. But that distinction matters less than people think. In containerised environments, CI/CD runners, multi-tenant hosts, and shared infrastructure, a low-privileged shell is not hard to get. DirtyClone turns that foothold into full system compromise. Not every Linux kernel is affected. Early reports point to specific kernels and backports carrying this regression. But if you are running unpatched kernels anywhere in production, now is the time to find out. The hardening principles do not change. Least privilege everywhere. Minimal attack surface. Rapid patching cycles. Behavioral monitoring that catches anomalous privilege activity before it becomes an incident. The kernel is the foundation. When the foundation has cracks, everything above it is at risk. My name is Azubuike Ibe and I write about the vulnerabilities hiding inside infrastructure most people consider too mature to fail. Share this with an engineer on your team managing Linux in any multi-tenant or containerised environment. #Cybersecurity #LinuxKernel #DirtyClone #DevSecOps #AppSec

    Post summary

    The text announces the new CVE‑2026‑43503 vulnerability, providing technical details about a local privilege escalation in the Linux kernel, without evidence of PoC, exploit code, or active exploitation.

    03087122
    1.5K followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.1--
OSlinuxlinux_kernel7.1--
OSlinuxlinux_kernel7.1--
OSlinuxlinux_kernel7.1--

Explore more