bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud
Thursday, August 20, 2026

Amazon Linux Kernel DirtyFrag Vulnerability Requires Immediate Patching

Amazon Linux kernels are vulnerable to DirtyFrag (CVE-2026-31431), a privilege escalation flaw affecting xfrm_user, esp4/esp6, and ipcomp4/ipcomp6 modules. Unprivileged users can exploit this to access kernel memory and escalate privileges on systems allowing socket creation or user namespaces. Action required: update your Amazon Linux systems immediately.

source: [aws/security-bulletin]