#DirtyFrag
My server got hit because I made a stupid mistake. But I got to fight a live root compromise while dual-wielding LLMs, which is bleakly embarrassing but also worth sharing.

Maybe useful: @doublepulsar.com @thedfirreport.bsky.social @abuse-ch.bsky.social. Probably nothing new, but new to me!
GitHub - lukeslp/redtail-ioc: IOCs and a read-only triage checklist from a real Linux root compromise: RedTail miner, XorDDoS persistence, MoneroOcean miner, DirtyFrag LPE (CVE-2026-43284/43500). CC0.
IOCs and a read-only triage checklist from a real Linux root compromise: RedTail miner, XorDDoS persistence, MoneroOcean miner, DirtyFrag LPE (CVE-2026-43284/43500). CC0. - lukeslp/redtail-ioc
github.com
July 7, 2026 at 11:52 PM
New update is out as of yesterday morning that patches the DirtyFrag exploit. This one is similar to CopyFail which we also patched a few days ago.

Stay safe out there. Remember these two if you ever wonder why we care so much about automatic updates!
May 9, 2026 at 9:00 AM
this means we need dirtyfrag on nixpkgs
nixos users stay WINNING as usual. even after patching nix-specific paths (eg. `/usr/bin/su` -> `/run/wrappers/bin/su`) in both exploits they just won't work. copy fail 2 fails on PAM auth because `nullok` is not enabled on auth and dirtyfrag throws EKEYREJECTED in rxrpc (idk why). interesting ∪・ω・∪
May 8, 2026 at 3:44 PM
this user has been marked safe from the hentai virus
May 10, 2026 at 3:55 PM
May 7, 2026 at 10:56 PM
Can someone hurry along and formally verify the linux kernel and all the GNU utilities already? This is getting very annoying.
GitHub - V4bel/dirtyfrag
Contribute to V4bel/dirtyfrag development by creating an account on GitHub.
github.com
May 8, 2026 at 5:52 AM
Et c'est reparti... github.com/V4bel/dirtyf...
LPE Linux de la même veine que copy.fail. Il faut blacklister les modules esp4 esp6 et rxrpc en attendant un correctif.
Un fichier dans modprobe.d avec "install esp4 /bin/false" et pareil pour esp6 et rxrpc doit bloquer l'exploit.
GitHub - V4bel/dirtyfrag
Contribute to V4bel/dirtyfrag development by creating an account on GitHub.
github.com
May 7, 2026 at 8:18 PM
The Linux kernel team is working on Killswitch, a new security feature that will temporarily disable some kernel functions until a patch is available

This is in response to the recent CopyFail and DirtyFrag disclosure debacles

lore.kernel.org/all/20260507...
May 10, 2026 at 4:59 PM
After DirtyFrag, DirtyClone exposes another Linux kernel flaw that may let local attackers gain root access on vulnerable systems.
linuxiac.com/linux-gets-d...

#Linux #Kernel #OpenSource #Security
Linux Gets Dirty Again: DirtyClone Kernel Flaw Can Lead to Local Root Access
After DirtyFrag, DirtyClone exposes another Linux kernel flaw that may let local attackers gain root access on vulnerable systems.
linuxiac.com
June 26, 2026 at 1:47 PM
Apparently copyfail2 and dirtyfrag are the same thing.
May 7, 2026 at 11:01 PM
Das anonymisierende Linux Tails ist als nächstes Notfallupdate in Version 7.7.3 erschienen. Es schließt die DirtyFrag-Lücke. #Security
Anonymisierendes Linux Tails: Notfallupdate 7.7.3 fixt DirtyFrag-Lücke
Das anonymisierende Linux Tails ist als nächstes Notfallupdate in Version 7.7.3 erschienen. Es schließt die DirtyFrag-Lücke.
www.heise.de
May 12, 2026 at 6:59 AM
nixos users stay WINNING as usual. even after patching nix-specific paths (eg. `/usr/bin/su` -> `/run/wrappers/bin/su`) in both exploits they just won't work. copy fail 2 fails on PAM auth because `nullok` is not enabled on auth and dirtyfrag throws EKEYREJECTED in rxrpc (idk why). interesting ∪・ω・∪
May 8, 2026 at 8:29 AM
DirtyFrag: Linuxカーネルのローカル権限昇格脆弱性について現時点で分かっていること | ワルブリックス株式会社
https://www.walbrix.co.jp/article/dirtyfrag-linux-lpe.html
DirtyFrag: Linuxカーネルのローカル権限昇格脆弱性について現時点で分かっていること | ワルブリックス株式会社
2026年5月に公開されたLinuxカーネルのローカル権限昇格脆弱性 DirtyFrag について、影響、暫定緩和策を管理者向けに整理する。
www.walbrix.co.jp
May 8, 2026 at 7:33 AM
Excellent article en français sur la faille Dirty Frag aka la double CVE-2026-43284 et CVE-2026-43500 !
Je vous recommande grandement sa lecture !

blog.marcfredericgomez.fr/dirty-frag-c...

#Linux #LPE #DirtyFrag
Dirty Frag (CVE-2026-43284 et CVE-2026-43500) – Blog de Marc Frédéric GOMEZ
blog.marcfredericgomez.fr
May 9, 2026 at 7:34 AM
SOMEONE COMBINED GHOSTLOCK + DIRTYFRAG.
🤯
AND STILL BYPASSES ANY INTEGRITY CHECK. 💀
This is temporary root btw. You reboot and the phone goes back to normal.
Project related to this:
github.com/BuSung-dev/R...
September 22, 2026 at 12:36 AM
so ig nixos isn't safe in the end, but at least it's way harder to execute dirtyfrag on it
May 8, 2026 at 1:41 PM
Atenció amics i amigues sysadmin !!!!
La nova vulnerabilitat del kernel de Linux (Dirty Frag) és greu. Encara no hi ha patch. Però en el moment que isca, vos recomane reinstal·lar el nou kernel. Sobre tot en servidors.
github.com/V4bel/dirtyf...
GitHub - V4bel/dirtyfrag
Contribute to V4bel/dirtyfrag development by creating an account on GitHub.
github.com
May 9, 2026 at 2:46 AM
On to DirtyFrag?
May 8, 2026 at 5:45 PM
GitHub - V4bel/dirtyfrag
Contribute to V4bel/dirtyfrag development by creating an account on GitHub.
github.com
May 8, 2026 at 12:43 PM
Dirty Frag: Universal Linux LPE
GitHub - V4bel/dirtyfrag
Contribute to V4bel/dirtyfrag development by creating an account on GitHub.
github.com
May 7, 2026 at 9:42 PM
Yeah, so, this. Again, today. #DirtyFrag #sigh
Be kind to your #HPC sysadmins today, they're not having a good day...

#copy.fail
May 8, 2026 at 5:40 PM