Copy Fail and DirtyFrag: Linux Page Cache Bugs in the Wild
ID: 4132bf95-56ad-56c3-873b-e827b8d41313
STIX ID: report--4132bf95-56ad-56c3-873b-e827b8d41313
Feed Name: Elastic Security Labs
This report analyses two related Linux kernel privilege-escalation issues—Copy Fail (CVE-2026-31431) and DirtyFrag—showing how subtle page-cache corruption via legitimate kernel interfaces (AF_ALG/AF_RXRPC and splice()) can reliably yield local root. It documents public proof-of-concepts and in-the-wild exploitation (Copy Fail), and provides practical detection rules (auditd, EQL/ES|QL queries, syscall aggregation), mitigation guidance (kernel updates, module blacklisting, page-cache drop, and unprivileged namespace restrictions), and recommended audit rules to improve defender visibility.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
