Canonical Confirms Ubuntu Fixes for DirtyClone Linux Kernel Flaw
'Canonical has published additional details about DirtyClone, the recently disclosed Linux kernel vulnerability that can allow a local user to gain root privileges on affected systems. DirtyClone, tracked as CVE-2026-43503, was publicly disclosed by JFrog on June 25, 2026, and has a CVSS 3.1 score of 8.8 (high severity). Canonical notes the issue was responsibly disclosed to Linux kernel maintainers earlier, with the CVE record published on May 23. The first Ubuntu security updates addressing this vulnerability were released on June 2. Just a reminder that DirtyClone is a local privilege escalation flaw, allowing a local user to gain root access. For container deployments running third-party workloads, Canonical notes the vulnerability could enable container escapes, although no proof-of-concept exploit for this scenario has been published. DirtyClone affects the same components as the previously disclosed Dirty Frag and Fragnesia vulnerabilities. Systems where administrators have already blocked the affected kernel modules as mitigation for those issues are also protected against DirtyClone. For Ubuntu users, the fix is provided through Linux kernel image packages. The following kernel versions include the fix: - Ubuntu 26.04 LTS: 7.0.0-22.22 - Ubuntu 20.04 LTS with 5.15 kernel: 5.15.0-181.191~20.04.1 - Ubuntu 22.04 LTS: 5.15.0-181.191 - Ubuntu 24.04 LTS: 6.8.0-124.124 - Ubuntu 25.10: 6.17.0-35.35 Importantly, Ubuntu 20.04 LTS systems still using the 5.4 kernel remain affected. Older releases, including 14.04 LTS, 16.04 LTS, and 18.04 LTS, are also listed as affected in Canonical’s table.' -- source: https://linuxiac.com/canonical-confirms-ubuntu-fixes-for-dirtyclone-linux-ke... Cheers, Peter
participants (1)
-
Peter Reutemann