A severe Linux kernel vulnerability named Dirty Frag has been disclosed, granting root access on most Linux systems dating back to 2017. The exploit was revealed after an unrelated third party broke the embargo set by the Linux kernel team.
Exploit leverages zero-copy page cache write
Dirty Frag is a local privilege escalation that exploits a zero-copy page cache write operation. The vulnerability was introduced in kernel commit cac2661c53f3 from 2017 and also affects commit 2dc334f1a63a. The affected modules are esp4, esp6, and rxrpc.

The vulnerability was reported to the Linux kernel team on April 30. As of the time of writing, no patches are available. Users can mitigate the risk by disabling the esp4, esp6, and rxrpc modules.
The exploit resembles the Copy Fail vulnerability in its impact. The Linux kernel team has not yet confirmed when a fix will be released.



Discussion
0 comments
Log in to join the thread with a thoughtful take, question, or correction.