Copy Fail / DirtyFrag / Fragnesia
Three related Linux kernel local privilege escalation vulnerabilities disclosed between April and May 2026, CopyFail (CVE-2026-31431), DirtyFrag (CVE-2026-43284 / CVE-2026-43500), and Fragnesia (CVE-2026-46300) all share the same core exploitation primitive — an unprivileged local user abuses an in-kernel in-place decryption path (via AF_ALG authencesn, xfrm-ESP, or ESP-in-TCP respectively) combined with repeated splice() syscalls to corrupt the page cache of a setuid binary such as /usr/bin/su, then executes it to obtain a root shell without any authentication; all three have public proof-of-concept code, affect Linux kernels from 4.14 onward, and can be mitigated by blacklisting the esp4, esp6, rxrpc, and algif_aead kernel modules until patched kernels are deployed.
CQL

