Rich Mingin (PLUG) via plug on 8 May 2026 06:33:58 -0700


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

Re: [PLUG] New Linux 'Dirty Frag' zero-day gives root on all major distros


I just want to note that I spent a chunk of time yesterday running the POC code against pretty much every distro, and *nobody* was unaffected. Unless you configure and build your own kernel with some rather esoteric setup (disabling several pieces of kernel crypto support), you are affected, all the way up through kernel 7.0.4.

If you have work/prod machines to manage, I’d lock down all users as much as possible till fixes start getting disseminated, since anyone with any login can get root until then.

On Fri, May 8, 2026 at 08:15 jeffv via plug <plug@lists.phillylinux.org> wrote:
New Linux 'Dirty Frag' zero-day gives root on all major distros

https://www.bleepingcomputer.com/news/security/new-linux-dirty-frag-zero-day-with-poc-exploit-gives-root-privileges/


Dirty Frag works by chaining two separate kernel flaws, the xfrm-ESP
Page-Cache Write vulnerability and the RxRPC Page-Cache Write
vulnerability, to modify protected system files in memory without
authorization and achieve privilege escalation.

Also, while Dirty Frag belongs to the same class as the Dirty Pipe and
Copy Fail Linux vulnerabilities, it exploits the fragment field of a
different kernel data structure.
___________________________________________________________________________
Philadelphia Linux Users Group         --        http://www.phillylinux.org
Announcements - http://lists.phillylinux.org/mailman/listinfo/plug-announce
General Discussion  --   http://lists.phillylinux.org/mailman/listinfo/plug
___________________________________________________________________________
Philadelphia Linux Users Group         --        http://www.phillylinux.org
Announcements - http://lists.phillylinux.org/mailman/listinfo/plug-announce
General Discussion  --   http://lists.phillylinux.org/mailman/listinfo/plug