Post #2250883
2026-05-07 22:56 UTC
https://lwn.net/Articles/1071719/
#DirtyFrag is a broken embargo.
Local Privilege Escalation to root.
Public working exploit. No CVE assigned yet.
No fix in sight.
<edit> 7.0.5 was just released which has a fix </edit>
<edit 2> CVE-2026-43284 has been assigned</edit 2>
#infosec #cyber #tsunamiofvulns #CVE-2026-43284
This is the documentation & exploit of DirtyFrag:
https://github.com/V4bel/dirtyfrag/blob/master/README.md
Replies (3)
-
@mcfly@milliways.social 2026-05-08 07:20
There seen to be a fix in commit https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/?id=f4c50a4034e62ab75f1d5cdd191dd5f9c77fdff4 That fix made it into 7.0.5 which was released 30 mins (?) ago https://cdn.kernel.org/pub/linux/kernel/v7.x/ChangeLog-7.0.5 #dirtyfrag
-
@mcfly@milliways.social 2026-05-08 14:22
and we have another one. This one with CVE. #dirtyfrag #CVE-2026-43500
-
@jon@domum.social 2026-05-08 00:05
@mcfly@milliways.social It's making for an interesting evening but there is a simple mitigation given in the github (as long as you don't actually need any of the three kernel modules it blocks from loading...) https://github.com/V4bel/dirtyfrag#mitigation