Linux Kernel Dirty Frag Local Privilege Escalation | MSSP Advisory
High
DateMay 8, 2026
📋Executive Summary
Dirty Frag is a Linux local privilege escalation vulnerability in kernel networking components including esp4, esp6, and rxrpc that allows reliable escalation from unprivileged user to root access. Attackers can exploit this after gaining initial access through SSH, web shells, containers, or compromised low-privileged accounts. Microsoft reports active exploitation in the wild with Defender providing detection coverage.
⚠️Why It Matters for MSSPs
Your Linux-based RMM agents, monitoring tools, and jump boxes become root-level compromised if an attacker gets any foothold on those systems. Every client running Linux servers, containers, or appliances faces the same escalation risk, and they expect you to know about kernel-level threats that turn limited breaches into full system compromise.
📬
Get notified when client-ready advisories like this are published each week.
Join the MSSP Watchlist →🏷️Threat Category
Vulnerability Disclosure
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.