Dirty Frag Linux Kernel Exploit Grants Root Access on Systems Since 2017

Dirty Frag, a severe Linux kernel vulnerability since 2017, grants root access on most systems. No patch available; disable esp4, esp6, rxrpc modules to mitigate.

Dirty Frag Linux Kernel Exploit Grants Root Access on Systems Since 2017

A severe kernel vulnerability named Dirty Frag has been disclosed, granting root access on most Linux systems dating back to 2017. The exploit was revealed after an unrelated third party broke the embargo set by the Linux kernel team.

Exploit leverages zero-copy page cache write

Dirty Frag is a local privilege escalation that exploits a zero-copy page cache write operation. The vulnerability was introduced in kernel commit cac2661c53f3 from 2017 and also affects commit 2dc334f1a63a. The affected modules are esp4, esp6, and rxrpc.

Linux kernel vulnerability Dirty Frag root access exploit
The Dirty Frag exploit affects Linux systems since 2017.

The vulnerability was reported to the Linux kernel team on April 30. As of the time of writing, no patches are available. Users can mitigate the risk by disabling the esp4, esp6, and rxrpc modules.

The exploit resembles the Copy Fail vulnerability in its impact. The Linux kernel team has not yet confirmed when a fix will be released.

Discussion

0 comments

Log in to join the thread with a thoughtful take, question, or correction.

Add to the discussion