Scroll to navigation

Linux Vulnerability Mitigation(7) Miscellaneous Information Manual Linux Vulnerability Mitigation(7)

Name

Linux Vulnerability Mitigation - Mitigation for some Linux kernel security vulnerabilities

Description

The Linux kernel has recently got some local privilege escalation bugs.

CVE-2026-31431: Copy Fail

Copy Fail (<https://copy.fail/>) is a vulnerability in the Linux kernel that allows unauthorized privilege escalation.
It was disclosed by security firm Theori to the public on 29 April 2026 and is fixed as of Linux version 7.0.5 (Debian: 7.0.4-1).

CVE-2026-43284/CVE-2026-43500: Dirty Frag

Dirty Frag (<https://github.com/V4bel/dirtyfrag>) is a vulnerability in the Linux kernel that allows unauthorized privilege escalation.
It was disclosed by Hyunwoo Kim to the public on 7 May 2026 and is fixed as of Linux version 7.0.6.

CVE-2026-46300: Fragnesia

Fragnesia (<https://github.com/v12-security/pocs/tree/main/fragnesia>) is a vulnerability in the Linux kernel that allows unauthorized privilege escalation.
It was disclosed by Sam James to the public on 13 May 2026.

Interactive usage

The linux-vulnerablility-mitigation package applies mitigations based on the admins selection via debconf:

sudo dpkg-reconfigure linux-vulnerablility-mitigation

The debconf dialog allows to choose individual mitigations, as well as the following special values:

will install all mitigations
will not install any mitigation (noop)

Non-interactive usage

The linux-vulnerablility-mitigation package can be preseeded with debconf:

TMPFILE="$(mktemp)"
cat > "${TMPFILE}" << EOF
linux-vulnerablility-mitigation linux-vulnerablility-mitigation/mitigations multiselect all
EOF
cat "${TMPFILE}" | debconf-set-selections
dpkg-reconfigure -fnoninteractive -pcritical linux-vulnerablility-mitigation
rm -f "${TMPFILE}"

Instead of selecting 'all' mitigations, individual mitigations can be specified by their CVE number:

linux-vulnerablility-mitigation linux-vulnerablility-mitigation/mitigations multiselect CVE-2026-31431, CVE-2026-43284, CVE-2026-43500

Authors

linux-vulnerability-mitigation were written by Daniel Baumann <<daniel@debian.org>> and others.

linux-vulnerability-mitigation Linux