Ongoing updates on Copy.fail and variants
UnratedCVE-2026-46300 · Published May 13, 2026 · updated Sep 25, 2026
Bulletin ID: 2026-030-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 05/13/2026 18:30 PM PDT Last Updated Date: 06/17/2026 10:30 AM PDT ⚠️This is an ongoing issue. This bulletin will be updated as more information becomes available. Description: AWS is aware of the " copy.fail " or "DirtyFrag" class of issues - a set of privilege escalation issues affecting the Linux Kernel. We will update this bulletin as more information becomes available. Please see below for current patching timelines for affected services related to the " Copy.fail " kernel issue and all its variants. AWS recommends that customers apply all updates addressing these issues as soon as they are available. Please email aws-security@amazon.com with any security questions or concerns. CVE-2026-46300 (also known as "Fragnesia") CVE-2026-46300 is a local privilege escalation that affects the Linux Kernel module espintcp.Amazon Linux and Bottlerocket don't provide this module, and are not affected. For more information see Security Bulletin (ID: 2026-029-AWS) . Updates on additional services will be published as soon as they become available. &...
Affected versions
Details and references
Bulletin ID: 2026-030-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 05/13/2026 18:30 PM PDT Last Updated Date: 06/17/2026 10:30 AM PDT ⚠️This is an ongoing issue. This bulletin will be updated as more information becomes available. Description: AWS is aware of the " copy.fail " or "DirtyFrag" class of issues - a set of privilege escalation issues affecting the Linux Kernel. We will update this bulletin as more information becomes available. Please see below for current patching timelines for affected services related to the " Copy.fail " kernel issue and all its variants. AWS recommends that customers apply all updates addressing these issues as soon as they are available. Please email aws-security@amazon.com with any security questions or concerns. CVE-2026-46300 (also known as "Fragnesia") CVE-2026-46300 is a local privilege escalation that affects the Linux Kernel module espintcp.Amazon Linux and Bottlerocket don't provide this module, and are not affected. For more information see Security Bulletin (ID: 2026-029-AWS) . Updates on additional services will be published as soon as they become available. CVE-2026-43284 and CVE-2026-31431 (also known as "DirtyFrag" or copy.fail 2) CVE-2026-43284 and CVE-2026-31431 are a set of privilege escalation issues affecting a number of Linux Kernel modules, including xfrm_user, esp4, and esp6. For more information see: https://aws.amazon.com/security/security-bulletins/2026-027-aws/ . Affected services: Amazon Linux: Amazon Linux kernels 4.14, 5.4, 5.10, 5.15, 6.1, 6.12, and 6.18 are affected. AWS has released updates to Amazon Linux addressing this issue. We recommend that customers apply the available kernel updates for their environment. Bottlerocket: AWS has released updates addressing this issue with Bottlerocket v1.61.0. Customers should apply all available updates to their Bottlerocket hosts. ECS: All regions have been patched. Customers should apply all available updates. EKS: Updates for EKS-optimized AMIs have been published. Customers should apply all available updates. EMR: AWS has released all updates for EMR. Customers should apply all available updates. Fargate: Platform versions are released with patches in all regions. Customers should apply all available updates. AWS Deep Learning AMIs (DLAMI): AWS Deep Learning AMIs are affected. Updated AMIs for Neuron Base, Trainium, and Inferentia have been released. Customers using Neuron DLAMIs on EC2 should launch new instances with the latest Neuron DLAMI version. Sagemaker: SageMaker has rolled out patched compute environments across all services for CVE-2026-43284 and CVE-2026-43500: - All Notebook instances created or restarted after May 20, 2026 automatically include the patched kernel. Customers should restart their notebooks to pick up the latest kernel version. - Amazon Linux 2023 (AL2023) K8 Hyperpod clusters are patched. Customers should apply all available updates. - All SageMaker Inference Endpoints, Studio, and Canvas resources created, restarted, or updated after May 26, 2026 include the patched kernel. Customers should restart their Studio and Canvas apps to pick up the latest kernel version. - All SageMaker Training Jobs, Processing Jobs, and Batch Transform jobs launched after June 4, 2026 automatically use the patched kernel. No customer action required. No customer action is required for Fargate/ ECS Managed instances customers. CVE-2026-31431 (also known as copy.fail) CVE-2026-31431 is a privilege escalation issue affecting the Linux Kernel module algif_aead. For more information see: https://aws.amazon.com/security/security-bulletins/2026-026-aws/ . Affected services: Amazon Linux: Amazon Linux kernels 4.14, 5.4, 5.10, 5.15, 6.1, 6.12, and 6.18 are affected. AWS has released updates to Amazon Linux addressing this issue. We recommend that customers apply the available kernel updates for their environme
- Severity from
- no source yet
- Also known as
- CVE-2026-43284, CVE-2026-31431, CVE-2026-43500
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 18 | Remote Code Execution in amazon-redshift-python-driver | Unrated | No fix yet |
| May 14 | Missing integrity verification in Triton inference handler in Amazon SageMaker Python SDK | Medium6.4 | v2.257.2andv3.8.0 |
| May 14 | Issue with Amazon SageMaker Python SDK - Model artifact integrity verification issues... | Unrated | No fix yet |
| May 14 | Heap out-of-bounds read in coreMQTT MQTT5 property parsing | Unrated | No fix yet |
| May 13 | Fragnesia Local Privilege Escalation report via ESP-in-TCP in the Linux Kernel | Unrated | No fix yet |
| May 8 | Remote Code Execution via Unsafe Class Loading in Amazon Redshift JDBC Driver | Unrated | No fix yet |