M5 statement on Vulnerability Affecting Linux - CVE-2026-43503
On May 23, 2026, information was published regarding CVE-2026-43503, commonly referred to as "DirtyClone", a Linux kernel local privilege escalation vulnerability rated as high severity due to its potential security impact.
M5 Technologies has reviewed the published information and assessed the potential impact on Mediatrix products. Based on this evaluation, Mediatrix gateways, ATAs, and Sentinel series products are not affected by this vulnerability.
Impact for Mediatrix customers
Mediatrix firmware is not impacted, the affected Linux modules esp4, esp6, or rxrpc are not loaded. As a result, these products are not susceptible to CVE-2026-43503.
Impact for Sentinel CS customers
The Sentinel CS SBC operates as a service on a Linux operating system. Customers using this application should continue to follow standard security best practices and ensure that the underlying host operating system remains up to date and protected against known vulnerabilities.
To help reduce potential exposure, M5 recommends that Sentinel CS customers:
• Apply the latest Linux security patches and updates provided by their operating system vendors.
• Follow their organization’s standard security and system maintenance procedures.
This document contains information that is proprietary to M5 Technologies.
M5 Technologies reserves all rights to this document as well as to the Intellectual Property of the document and the technology and know-how that it includes and represents.
This publication cannot be reproduced, neither in whole nor in part, in any form whatsoever, without written prior approval by M5 Technologies.
M5 Technologies reserves the right to revise this publication and make changes at any time and without the obligation to notify any person and/or entity of such revisions and/or changes.