Copy Fail, Dirty Frag, and Fragnesia kernel vulnerabilities
akhuettel
120 points
46 comments
May 19, 2026
Related Discussions
Found 5 related stories in 89.5ms across 8,303 title embeddings via pgvector HNSW
- Fragnesia Made Public as Latest Linux Local Privilege Escalation Vulnerability mikece · 37 pts · May 13, 2026 · 70% similar
- "Dirty Frag" (CVE-2026-43284): The Second Linux Root Exploit in Eight Days ggallas · 31 pts · May 09, 2026 · 64% similar
- 'Dirty Frag' exploit leaks out, gives root on most Linux machines lschueller · 15 pts · May 08, 2026 · 64% similar
- Four stable kernels with partial fixes for Dirty Frag Brajeshwar · 18 pts · May 08, 2026 · 63% similar
- CVE-2026-31431: Copy Fail vs. rootless containers averi · 59 pts · May 05, 2026 · 62% similar
Discussion Highlights (4 comments)
clircle
Is Gentoo an outlier or do all Linux distributions deal with this problem?
himata4113
Expanding on gentoo's recommendations: I wonder if we should just universally accept that live patching should become part of the linux kernel? An automatic job that updates (much like some system packages in some distros) that installs (signed) live patches from upstream? Of course we would run into a problem where a malicious patch can now be distributed reliably to hundreds of thousands of machines, but we already have that at a lower level with normal application updates. Canonical has thus far proved that it can be safe, but they're also a massive organization that is locking this feature for $200/yr for any commercial use. It would be neat if such patches could retroactively replace tagged functions that have identical sematics so that means it would automatically get backported without extra effort from the maintainers.
yjftsjthsd-h
> We recommend exploring ways to automate upgrading your kernel Like, running emerge -u @world on a regular basis, or ... /me searches Okay, so https://wiki.gentoo.org/wiki/Live_patching exists but says, > A note of caution: Kernel live patching is risky. Count on hard freezing or panics to become normal... That's not encouraging. --- Another approach: Can we make the kernel vulns less important? Has anyone had luck moving more things to run under gvisor or firecracker or such?
romaniv
Clearly, the future is LLM-generated patches that get instantly vibecoded and installed on all machines without any human review. In fact, this is such a good idea that it should be illegal and impossible to run your computer without being connected to such a system. There are no other alternatives. /sarcasm