DirtyClone CVE-2026-43503 (CVSS 8.8): high-severity DirtyFrag family variant. __pskb_copy_fclone() drops SKBFL_SHARED_FRAG during packet cloning in XFRM/IPsec path.
Unprivileged users with CAP_NET_ADMIN (via user namespaces) gain root by manipulating page-cache-backed socket buffers. Silent attack — no kernel logs or audit traces.
Patch merged mainline May 21, 2026 (v7.1-rc5). Systems with partial DirtyFrag patches remain exploitable. Full patch chain required: CVE-2026-43284, CVE-2026-43500, CVE-2026-46300, CVE-2026-43503.
Mitigation: update kernel or disable unprivileged user namespaces.