DirtyFrag

It is a Linux local privilege escalation (LPE) named Dirty Frag. Combination of CVE-2026-43284 and CVE-2026-43500.

Affected kernel modules seem to be esp4, esp6 and rxrpc.

Mitigation

   1 sudo bash
   2 sh -c "printf 'install esp4 /bin/false\ninstall esp6 /bin/false\ninstall rxrpc /bin/false\n' > /etc/modprobe.d/dirtyfrag.conf; rmmod esp4 esp6 rxrpc 2>/dev/null; echo 3 > /proc/sys/vm/drop_caches; true"
   3 
   4 cat /etc/modprobe.d/dirtyfrag.conf 

DirtyFrag (last edited 2026-05-09 10:17:16 by vitor)