Linux kernel developers are reviewing an emergency runtime mitigation called Killswitch after public disclosure of multiple local privilege escalation flaws, including Copy Fail (CVE-2026-31431) and the chained Dirty Frag bugs (CVE-2026-43284, CVE-2026-43500). Dirty Frag, disclosed by researcher Hyunwoo Kim and discussed by Red Hat and other outlets, affects kernel networking paths tied to IPSec ESP and RxRPC and can let an unprivileged local user gain root on many distributions. Copy Fail, a separate nine-year-old flaw in AF_ALG cryptographic sockets, was also reported as enabling reliable local root escalation by allowing controlled writes into the kernel page cache of readable files.
Government and vendor guidance warned that public proof-of-concept exploit code is available and that risk increases if the local flaws are paired with remote code execution. The Canadian Centre for Cyber Security said no universal fix was immediately available across all stable kernels and urged defenders to identify exposed systems, restrict local access, reduce privileges, regenerate initramfs, and disable vulnerable modules where possible. In parallel, a GitHub project circulated shell-based stopgap patching to disable or rename affected modules on running systems, while the proposed Killswitch mechanism would let administrators force selected kernel functions to return safely without executing until patched kernels can be deployed.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Linux kernel developers began reviewing Sasha Levin's proposed Killswitch mechanism, which would let administrators disable vulnerable kernel functions at runtime as a stop-gap defense between disclosure and patch deployment. The proposal was still under review and had not yet been merged.
A GitHub repository named cf-df was published with a shell script to mitigate copy.fail and Dirty Frag by disabling or renaming vulnerable kernel modules on running Linux hosts. The repository documented operational limitations, including no support for vulnerable functionality built directly into the kernel.
The Canadian Centre for Cyber Security issued Alert AL26-011 warning that CVE-2026-43284 and CVE-2026-43500 could be chained for local privilege escalation and root compromise. It said public proof-of-concept exploits existed and that no universal fix was yet available across all stable kernels.
Researcher Hyunwoo Kim publicly disclosed Dirty Frag on May 7, 2026. The issue consists of CVE-2026-43284 and CVE-2026-43500, and reporting says disclosure was accelerated after a public upstream patch enabled rapid exploit development by another researcher.
Theori publicly disclosed Copy Fail (CVE-2026-31431), a nine-year-old AF_ALG cryptographic socket flaw that can enable reliable local root escalation by letting an unprivileged user write controlled bytes into the kernel page cache of any readable file.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcehelpnetsecurity.com
Open sourcecyber.gc.ca
Open sourcegithub.com
Open sourceseclists.org
Open sourceafflicted.sh
Open sourceopennet.ru
Open sourceopennet.ru
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.