Dirty Frag Linux Kernel Hands Out Root
Linux kernel chain gives unprivileged users root on every major distro. Researchers call it Dirty Frag, a page-cache overwrite like Copy Fail.
Chain hits CVE-2026-43284 in ESP IPsec and CVE-2026-43500 in RxRPC. Local users splice shared pages into skbs, then decrypt in place for 4-byte writes to su or passwd. Public PoC available, CVSS 7.8.
Strikes kernels since 4.11 for ESP, 6.5 for RxRPC across Ubuntu 24.04, RHEL 8-10, Fedora, AlmaLinux, openSUSE, CentOS Stream. Unpatched in distro kernels.
Mainline patched ESP via commit f4c50a4034e6, RxRPC fix pending.
