Fast response to the critical "Dirty Frag" Linux vulnerability

Fast response to the critical "Dirty Frag" Linux vulnerability

On 7 May 2026 the internet learned of a serious security vulnerability in the Linux operating system — a vulnerability named “Dirty Frag”. The news went around the tech world the same afternoon, because it does not affect just a few servers or a particular company — it affects practically every Linux server that runs today’s internet.

What is “Dirty Frag” and why is it dangerous?

Without too many technical details: the vulnerability lets an attacker take complete control of a server — which in practice means access to all data and sites, and the ability to run the server as its owner.

Three things make “Dirty Frag” especially worrying:

  • It is more than nine years old. The bug has been in the Linux kernel since January 2017. All that time it was there, waiting, just not publicly known.
  • Almost everyone is affected. Ubuntu, Debian, Red Hat, Rocky Linux, AlmaLinux — every major distribution.
  • The disclosure came without warning. Standard industry practice is to give vendors time to prepare a patch before public disclosure (responsible disclosure). In this case the embargo was broken, and the details came out before Ubuntu, or any other distribution, managed to publish a fix.

Our response

At Anart Studio we reacted to the news the same evening. We identified exactly which of our servers were at risk, applied a temporary protective measure and verified that the work was completed successfully. The whole process, from the first news to full protection of every server, took less than two hours.

  1. We checked the state of all six servers in our infrastructure
  2. We applied a protective configuration that blocks the mechanism “Dirty Frag” uses
  3. We verified that every server was successfully protected

All of it before the official Ubuntu patch for the Linux kernel was even published.

What does it mean for our clients?

If your site or application is hosted with us, you did not have to do anything. Your data, sites, databases and files are safe, and everything that happened behind the scenes stayed invisible. That is how it should be.

Security on the internet is not a static thing, and it is not a question of whether you “set good passwords and installed a firewall”. It is a daily process of monitoring, fast reaction and responsible infrastructure management. The “Dirty Frag” case is a good example of why it matters to have a partner who does that actively, not just one who “keeps the servers running”.

For those who want more detail

Technical details of the vulnerability are available from independent security sources:

Because the responsible disclosure schedule and embargo have been broken, no patches exist for any distribution. from the researcher’s original post on the oss-security mailing list

A permanent patch will be available as soon as Ubuntu publishes it — when that happens, we will update the Linux kernel on every server. Until then, our temporary measure blocks the attack completely.

All news