Dirty Frag: A new Linux privilege escalation vulnerability is already in the wild
ID: 5f6d4697-f395-5ea9-bb37-c19e244646d5
STIX ID: report--5f6d4697-f395-5ea9-bb37-c19e244646d5
Feed Name: Security Affairs
Dirty Frag is an unpatched, high-reliability Linux kernel privilege escalation vulnerability that allows an unprivileged local user to gain root by chaining the xfrm-ESP Page-Cache Write and RxRPC Page-Cache Write flaws. A public proof-of-concept is already available and the issue affects major distributions including Ubuntu, RHEL, Fedora, AlmaLinux, and CentOS Stream; temporary mitigation is to blocklist the esp4, esp6, and rxrpc kernel modules until official patches are released.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
