A week after Copy Fail , researcher Hyunwoo Kim disclosed a second Linux kernel flaw in the same broad area — IPsec ESP and rxrpc — that they have named Dirty Frag . The bug lives in the in-place decryption fast paths of esp4 , esp6 , and rxrpc : when a socket buffer carries paged fragments that are not privately owned by the kernel (e.g. pipe pages attached via splice(2) / sendfile(2) / MSG_SPLICE_PAGES ), the receive path decrypts directly over those externally-backed pages, exposing or corrupting plaintext that an unprivileged process still holds a reference to.
Like the Copy Fail vulnerability, Dirty Frag immediately yields root on all major distributions . Every supported AlmaLinux release is affected. Per Hyunwoo Kim’s public disclosure on oss-security (2026-05-07), the responsible-disclosure embargo was broken before distributions could coordinate, so no CVE identifiers have been allocated for either of the two bugs that make up Dirty Frag, and a working exploit is now publicly available.
If you run AlmaLinux on a multi-tenant host, container build farm, CI runner, or any system where untrusted users can get a shell, this one matters — and with public exploit code in the wild, it matters today.
More information the vulnerability:
Security is a top priority at AlmaLinux, and the severity of this flaw — combined with how trivial it is to exploit — meant we did not want to wait. Patches are not yet available from Red Hat, so our core team has built patched kernels using the upstream ESP fix (mainline commit f4c50a4034e6 ) backported and adapted to each supported AlmaLinux branch. The decision to ship these ahead of a CentOS Stream / RHEL update was made by our technical steering committee, ALESCo .
These kernels are available in the testing repository today . After the community has helped verify them, we will release them to the production repositories. This blog post will be updated when that happens.
It only takes a few steps to install and test the patched kernel from the testing repo.
Install the testing repo
Reboot to load the new kernel
Confirm you are running the patched kernel
The patched kernel versions are listed below. Use either of these commands:
We don’t recommend keeping the testing repo enabled after you’ve updated, unless you’ve done this on a truly non-production environment. If this is a production environment, you can disable the repo with this command:
If you encounter problems, please let us know as soon as you can, either in AlmaLinux chat , on bugs.almalinux.org .
AlmaLinux Kitten 10 is itself a development release and does not have a separate testing repository. The patched kernel is shipping directly to Kitten’s regular repository, so there is nothing extra to enable — just update and reboot:
Confirm with uname -r against the Kitten version listed below.
If updating and rebooting right now is not an option, you can neutralize the attack surface by blacklisting the affected modules. None of esp4 , esp6 , or rxrpc are loaded on a typical workload that does not use IPsec transport mode or AFS, so on most systems this is safe to apply immediately:
This writes a modprobe config that prevents the three modules from loading, and unloads them if they happen to be loaded already (the rmmod is best-effort and silent if the module isn’t present). The command is safe to run unchanged on all supported releases. To revert, remove /etc/modprobe.d/dirtyfrag.conf .
The Dirty Frag exploit works by corrupting page-cache pages of sensitive files (such as /etc/passwd or /usr/bin/su ). If you suspect the system may have already been targeted before you applied the mitigation, drop the page cache so any tampered pages are evicted and the read comes fresh from disk:
This is safe to run on a live system — it only frees clean cache and dentry/inode entries — and pairs well with the blacklist above.
A note on rxrpc.ko : on AlmaLinux it ships only as part of the kernel-modules-partner subpackage, which is published exclusively in the AlmaLinux Devel repository. kernel-modules-partner is not enabled by default and should not be installed on any production system — it carries unsupported partner-only modules and exposes additional code paths (including rxrpc , the second half of Dirty Frag) that are absent on a standard install. If you have it installed, the simplest mitigation is to remove it entirely:
Do not rely on this if you actually use IPsec ESP or AFS/rxrpc — those workloads will break. The proper fix is to install the patched kernel and reboot.
Thanks to Hyunwoo Kim for finding, responsibly disclosing, and writing up this vulnerability, and to Steffen Klassert for shepherding the upstream fix through the netdev tree.
Thanks to the AlmaLinux core team for turning around patched builds for every supported release within a day of the upstream fix landing, and to ALESCo for moving quickly to approve shipping ahead of upstream. And thank you in advance to everyone in the community who helps us test these kernels — that’s the part that gets them safely into production.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
