Minor impactResolvedCloud

Linode incident: [DirtyFrag] Linux Privilege Escalation Vulnerability

Linode reported this minor-impact incident on its official status page on May 8, 2026, 13:40 UTC. It was resolved after 59d 1h.

Right now Linode is operational. Live Linode status →

🔔 Get alerted when Linode has issuesFree · email alerts · no credit card
May 8, 2026, 13:40 UTC
started
Jul 6, 2026, 14:41 UTC
resolved
59d 1h
duration
Minor
impact

Affected components

  • AP-Northeast (Tokyo 2) Linode Kubernetes Engine
  • AP-Northeast-2 (Tokyo 2)
  • AP-Northeast-2 (Tokyo 2) Backups
  • AP-Northeast-2 (Tokyo 2) Block Storage
  • AP-Northeast-2 (Tokyo 2) NodeBalancers
  • AP-South (Singapore)
  • AP-South (Singapore) Backups
  • AP-South (Singapore) Block Storage
  • AP-South (Singapore) Linode Kubernetes Engine
  • AP-South (Singapore) NodeBalancers
  • AP-South (Singapore) Object Storage
  • AP-Southeast (Sydney)
  • AP-Southeast (Sydney) Backups
  • AP-Southeast (Sydney) Block Storage
  • AP-Southeast (Sydney) Linode Kubernetes Engine
  • AP-Southeast (Sydney) NodeBalancers
  • AP-West (Mumbai)
  • AP-West (Mumbai) Backups
  • AP-West (Mumbai) Block Storage
  • AP-West (Mumbai) Linode Kubernetes Engine
  • AP-West (Mumbai) NodeBalancers
  • AU-MEL (Melbourne)
  • AU-MEL (Melbourne) Backups
  • AU-MEL (Melbourne) Block Storage
  • AU-MEL (Melbourne) Linode Kubernetes Engine
  1. resolvedJul 6, 2026, 14:41 UTC

    We have completed our investigation and response to the "DirtyFrag" (CVE-2026-43500, CVE-2026-43284) and "Fragnesia" (CVE-2026-46300) vulnerabilities. We have published documentation articles with detailed guidance on available mitigations and recommended actions for affected systems. Customers can find more information and step-by-step instructions here: https://www.linode.com/docs/guides/cve-2026-31431-copy-fail-mitigation/ https://www.linode.com/docs/guides/dirty-frag-mitigation/ We encourage all customers to review the article and apply the appropriate mitigations to their environments. If you have questions or need assistance, please contact us at 855-454-6633 (+1-609-380-7100 Intl.) or email [email protected] for assistance.

  2. investigatingJun 5, 2026, 20:23 UTC

    We are responding to the publication of the most recent variation of the CopyFail[1] adjacent vulnerabilities “DirtyFrag” and “Fragnesia” with additional updates while we wait for upstream OS providers to release patches. Please see our detailed advisory[2] for more information on the current status, possible mitigation mechanisms, and our recommended actions. We will provide another update when more OS images have been updated and/or additional attack vectors are discovered. [1] https://www.linode.com/docs/guides/cve-2026-31431-copy-fail-mitigation/ [2] https://www.linode.com/docs/guides/dirty-frag-mitigation/

  3. investigatingMay 15, 2026, 17:28 UTC

    We are responding to the publication of the most recent variation of the CopyFail[1] adjacent vulnerabilities “DirtyFrag” and “Fragnesia” with additional updates while we wait for upstream OS providers to release patches. Please see our detailed advisory[2] for more information on the current status, possible mitigation mechanisms, and our recommended actions. We will provide another update when more OS images have been updated and/or additional attack vectors are discovered. [1] https://www.linode.com/docs/guides/cve-2026-31431-copy-fail-mitigation/ [2] https://www.linode.com/docs/guides/dirty-frag-mitigation/

  4. investigatingMay 9, 2026, 14:40 UTC

    We have updated our latest Linode kernel to version 7.0.5, which contains the upstream fix from kernel.org for the DirtyFrag vulnerabilities as well as the previous fixes for the recent CopyFail vulnerability. This kernel is available in Cloud Manager and we recommend customers using the Linode-compiled kernel update their configurations to this kernel. We are in parallel tracking the upstream Linux distributions and will provide another update when fixed versions have been released.

  5. investigatingMay 8, 2026, 13:40 UTC

    Akamai is aware of the recently disclosed “DirtyFrag”[1] vulnerability that followed the “CopyFail”[2] disclosure. This vulnerability is very similar in nature and has a similar impact, exploit path, and mitigation approach. We have not observed any related malicious exploits targeting our infrastructure and are continuing to address the vulnerability across our product portfolio and internal systems. As with “CopyFail”, we are advising customers to consider most Linux distributions to be at-risk until patched. Since the “DirtyFrag” vulnerability was disclosed prior to upstream patches having been made available, we are forced to wait for the different OS providers to create new releases or patches before we can integrate them into the versions we make available to customers. As this is a rapidly developing incident, we will provide further information regarding recommended actions, possible mitigations, and OS updates for all customers who may be affected. [1] https://github.com

What APIStatus.watch saw

Our 5-minute checks didn't record a change in Linode's overall status around this incident. Smaller or regional incidents often leave a provider's overall status green.

Other services with incidents at the same time

Overlapping incidents aren't necessarily related.

How often does Linode have incidents?

Linode reported 10 incidents in the last 90 days. A typical incident lasted 2h 15m. See Linode's uptime and incident history

Linode incident on May 8, 2026: [DirtyFrag] Linux Privilege Escalation Vulnerability · APIStatus.watch