How we contain Claude across products
…The VM has its own Linux kernel, its own filesystem, and its own process table. The user's selected workspace and .claude folder are mounted; nothing else on the host is visible…
CVE-2026-31525: Linux Kernel Privilege Escalation Flaw
Dirty Frag: Ongoing Linux Kernel Privilege Escalation Vulnerability Since 2017
Dirty Frag Linux kernel local privilege escalation vulnerability mitigations
Fragnesia: Linux Kernel Local Privilege Escalation via ESP-in-TCP
Fragnesia: Linux kernel local privilege escalation via ESP-in-TCP
To show you the most relevant results, we’ve omitted some entries very similar to those already shown. Repeat the search with the omitted results included.