Executive brief
A series of vulnerabilities known as 'Copy.fail' or 'DirtyFrag' affects the Linux kernel used across various AWS services. These flaws allow a user with limited access to a system to gain full administrative control (root privileges). This could lead to unauthorized data access, system modification, or disruption of services running on affected AWS infrastructure like Amazon Linux, EKS, and SageMaker.
Technical details
The 'Copy.fail' and 'DirtyFrag' class of vulnerabilities (including CVE-2026-43284, CVE-2026-31431, and CVE-2026-46300) are local privilege escalation (LPE) flaws in the Linux Kernel. These issues reside in various kernel modules including algif_aead, xfrm_user, esp4, and esp6. An attacker with local shell access can exploit these flaws to bypass security boundaries and gain root-level permissions. AWS is currently rolling out patches across its service portfolio, including Amazon Linux, Bottlerocket, Fargate, and SageMaker, with various completion dates through late May 2026.
Affected products
- Linux Linux Kernel 4.14, 5.4, 5.10, 5.15, 6.1, 6.12, 6.18
- AWS Amazon Linux
- AWS Bottlerocket
- AWS ECS-optimized AMI
- AWS EKS-optimized AMI
- AWS Fargate
- AWS SageMaker
Timeline
- 2026-05-13: advisory: Initial publication of AWS security bulletin 2026-030-AWS.
- 2026-05-14: disclosed: Public disclosure of the Copy.fail/DirtyFrag vulnerability class.
- 2026-05-15: patched: Patching deadline for several SageMaker and Fargate components.
- 2026-05-19: patched: Expected patch availability for Bottlerocket, ECS, and EKS AMIs.