[ << ALL_FEED ]

Dirty Frag 🐧

More in Phishing & sandbox

Dirty Frag 🐧💥

A week after the widely discussed Copy.Fail, researcher v4bel disclosed a new privilege escalation technique in the Linux kernel — Dirty Frag.

As of May 8, Dirty Frag has no CVE number and, more critically, no official patch from the kernel maintainers either. Dirty Frag belongs to the same class as Dirty Pipe and Copy.Fail, but uses a different mechanism: instead of pipe_buffer, it attacks the sk_buff structure.

The shared mechanisms of operation allow the exploit to be reliably blocked by behavioral expertise in PT Sandbox (Exploit.Linux.CVE-2022-0847.a, Exploit.Linux.CVE-2026-31431.a, Backdoor.Linux.Generic.a) — see the screenshot.

How does it work? 🧐

Dirty Frag is a chain of two vulnerabilities that complement each other to cover all major distributions:

1️⃣ Page-Cache Write (since 2017): provides the ability to write 4 bytes to the page cache, but requires the right to create user namespaces, which on some systems (e.g., Ubuntu) may be blocked by AppArmor.

2️⃣ RxRPC Page-Cache Write (since June 2023): does not require namespace privileges, but the rxrpc.ko module is present only in some distributions, including Ubuntu, where it is loaded by default.

By combining them, an attacker gets a working exploit on any system, which allows:

• Replacing suid files (e.g., /usr/bin/su) with their own version
• Modifying /etc/passwd by clearing the root user’s password

Who is at risk? ⛳️

Virtually all systems with a Linux kernel released since 2017. The researcher confirmed the exploit works on the following versions: Ubuntu 24.04.4, RHEL 10.1, openSUSE Tumbleweed, CentOS Stream 10, AlmaLinux 10, Fedora 44, and others.

How to protect yourself? 🔧

Since there is no official patch from the kernel maintainers yet, the only way to protect yourself is to immediately disable and unload the vulnerable kernel modules.

Command to disable:

sh -c "printf 'install esp4 /bin/false\ninstall esp6 /bin/false\ninstall rxrpc /bin/false\n' > /etc/modprobe.d/dirtyfrag.conf; rmmod esp4 esp6 rxrpc 2>/dev/null; true"

Some distributions (e.g., AlmaLinux) have started releasing their own patches without waiting for upstream.

UPD: the vulnerability has received an identifier — CVE-2026-43284, and a patch has been added to the kernel code (f4c50a4034e6).

#avlab #cve #linux #sandbox
@ptescalator (X, Max)

More from global_author

More from global_author

More in Phishing & sandbox