'Dirty Frag' Linux flaw one-ups CopyFail with no patches and public root exploit
ID: ee1f3552-9ede-5f21-83a5-c9042e66cfe1
STIX ID: report--ee1f3552-9ede-5f21-83a5-c9042e66cfe1
Feed Name: The Register (Security)
Threat Score
Dirty Frag is a newly public Linux local privilege escalation (LPE) that chains an xfrm-ESP bug (dating to 2017) with a 2023 RxRPC issue to allow unprivileged users to gain root on major distributions. The disclosure embargo collapsed after exploit details appeared publicly, leaving no coordinated patches or CVE yet and forcing administrators to rely on temporary mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
