Elektrine lite

← Feed

@mcfly@milliways.social

Post #2250883

2026-05-07 22:56 UTC

https://lwn.net/Articles/1071719/ #DirtyFrag is a broken embargo. Local Privilege Escalation to root. Public working exploit. No CVE assigned yet. No fix in sight. <edit> 7.0.5 was just released which has a fix </edit> <edit 2> CVE-2026-43284 has been assigned</edit 2> #infosec #cyber #tsunamiofvulns #CVE-2026-43284 This is the documentation & exploit of DirtyFrag: https://github.com/V4bel/dirtyfrag/blob/master/README.md

Replies (3)

  • @mcfly@milliways.social 2026-05-08 07:20

    There seen to be a fix in commit https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/?id=f4c50a4034e62ab75f1d5cdd191dd5f9c77fdff4 That fix made it into 7.0.5 which was released 30 mins (?) ago https://cdn.kernel.org/pub/linux/kernel/v7.x/ChangeLog-7.0.5 #dirtyfrag

    Open ##2312120

  • @mcfly@milliways.social 2026-05-08 14:22

    and we have another one. This one with CVE. #dirtyfrag #CVE-2026-43500

    Open ##2312121

  • @jon@domum.social 2026-05-08 00:05

    @mcfly@milliways.social It's making for an interesting evening but there is a simple mitigation given in the github (as long as you don't actually need any of the three kernel modules it blocks from loading...) https://github.com/V4bel/dirtyfrag#mitigation

    Open ##2312122