Splunk has published a new analytic to detect exploitation of the Linux kernel local privilege escalation flaw known as Dirty Frag, tied to CVE-2026-43284 and CVE-2026-43500. The detection maps to MITRE ATT&CK technique T1548.001 for abuse of setuid and setgid mechanisms, and is designed to identify attackers escalating privileges from an unprivileged Linux process to root.
The analytic looks for a distinctive exploit chain in Linux auditd telemetry: a burst of splice() or vmsplice() syscalls from a process launched from a user-writable path, followed within five minutes by execution of a setuid binary in the same audit session. Splunk said the detection is intended for Splunk Enterprise Security, is disabled by default, and requires Linux auditd data with audit rule keys for splice_user and process_creation; it also warned that high-I/O legitimate workloads may need tuning or allowlisting because the threshold was calibrated against the public V4bel proof of concept.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
Splunk Research published a detection analytic for identifying exploitation of the Linux kernel local privilege escalation issue Dirty Frag, associated with CVE-2026-43284 and CVE-2026-43500. The write-up describes detecting a syscall spray followed by execution of a setuid binary and notes calibration against the public V4bel proof of concept.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
codeby.net
Open sourceresearch.splunk.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.