Dirty Frag Linux Vulnerability Lets Attackers Gain Root Privileges, PoC Released
ID: 2ff2a5c7-b1eb-57a7-973f-7c6341c3143d
STIX ID: report--2ff2a5c7-b1eb-57a7-973f-7c6341c3143d
Feed Name: Cyber Press
A newly discovered Linux kernel vulnerability class named "Dirty Frag" enables deterministic local root escalation across many major distributions by chaining two page-cache write flaws (xfrm-ESP and RxRPC); a proof-of-concept was publicly released early, leaving systems exposed without official patches or CVE assignments. Administrators are advised to immediately mitigate exposure (e.g., block esp4/esp6/rxrpc modules) and monitor for unauthorized in-memory modifications until official kernel updates are released.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
