Dirty Frag LPE: CVE-2026-43284 and CVE-2026-43500 Deep Dive
ID: 8c35eded-9e23-5385-9dad-c824feef494d
STIX ID: report--8c35eded-9e23-5385-9dad-c824feef494d
Feed Name: Resources-2
Dirty Frag (CVE-2026-43284 and CVE-2026-43500) is a Linux kernel vulnerability class that chains two page-cache write bugs to achieve local root by planting read-only page-cache pages into sk_buff fragments and triggering in-place cryptographic writes. The report explains the technical mechanics (splice/zero-copy, sk_buff frags, in-place decrypt), concrete exploitation scenarios (48 4-byte writes to /usr/bin/su and overlapping writes to /etc/passwd), recommended temporary mitigations (blacklist esp/rxrpc modules and drop caches) and testing/simulation options via Picus.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
