table of contents
| Linux Vulnerability Mitigation(7) | Miscellaneous Information Manual | Linux Vulnerability Mitigation(7) |
Name¶
Linux Vulnerability Mitigation - Mitigation for some Linux kernel security vulnerabilities
Description¶
The Linux kernel has recently got some local privilege escalation bugs.
CVE-2026-31431: Copy Fail¶
Copy Fail (<https://copy.fail/>) is a vulnerability in the Linux kernel that allows unauthorized privilege escalation. It was disclosed by security firm Theori to the public on 29 April 2026 and is fixed as of Linux version 7.0.5 (Debian: 7.0.4-1).
CVE-2026-43284/CVE-2026-43500: Dirty Frag¶
Dirty Frag (<https://github.com/V4bel/dirtyfrag>) is a vulnerability in the Linux kernel that allows unauthorized privilege escalation. It was disclosed by Hyunwoo Kim to the public on 7 May 2026 and is fixed as of Linux version 7.0.6.
CVE-2026-46300: Fragnesia¶
Fragnesia (<https://github.com/v12-security/pocs/tree/main/fragnesia>) is a vulnerability in the Linux kernel that allows unauthorized privilege escalation. It was disclosed by Sam James to the public on 13 May 2026.
Interactive usage¶
The linux-vulnerablility-mitigation package applies mitigations based on the admins selection via debconf:
sudo dpkg-reconfigure linux-vulnerablility-mitigation
The debconf dialog allows to choose individual mitigations, as well as the following special values:
Non-interactive usage¶
The linux-vulnerablility-mitigation package can be preseeded with debconf:
TMPFILE="$(mktemp)"
cat > "${TMPFILE}" << EOF
linux-vulnerablility-mitigation linux-vulnerablility-mitigation/mitigations multiselect all
EOF
cat "${TMPFILE}" | debconf-set-selections
dpkg-reconfigure -fnoninteractive -pcritical linux-vulnerablility-mitigation
rm -f "${TMPFILE}"
Instead of selecting 'all' mitigations, individual mitigations can be specified by their CVE number:
linux-vulnerablility-mitigation linux-vulnerablility-mitigation/mitigations multiselect CVE-2026-31431, CVE-2026-43284, CVE-2026-43500
Authors¶
linux-vulnerability-mitigation were written by Daniel Baumann <<daniel@debian.org>> and others.
| linux-vulnerability-mitigation | Linux |