Dirty Frag LPE: CVE-2026-43284 and CVE-2026-43500 Deep Dive

Umut Bayram | 8 MIN READ

| May 20, 2026

Key Takeaways

  • Dirty Frag is a Linux kernel vulnerability class that chains two bugs (CVE-2026-43284 and CVE-2026-43500) to achieve root privileges on most Linux distributions by writing attacker-controlled data directly into read-only page cache pages via in-place cryptographic operations.
  • CVE-2026-43284 exploits a logic flaw in the IPsec ESP implementation that bypasses Copy-on-Write protections, enabling 48 separate 4-byte writes to overwrite the first 192 bytes of /usr/bin/su with a custom root-shell ELF executable.
  • CVE-2026-43500 exploits the RxRPC protocol's in-place fcrypt decryption to modify 12 bytes of /etc/passwd, clearing the root password field so the system accepts a blank password and grants a root shell without authentication.
  • The attack abuses the splice() system call's zero-copy mechanism to plant a reference to a read-only page cache page into an sk_buff frag, which the kernel then unknowingly overwrites during packet processing.
  • Picus Threat Library includes dedicated Dirty Frag simulation threats, allowing organizations to validate their security controls against this vulnerability.

Recently, a powerful vulnerability class known as "Dirty Frag" was discovered and reported by Hyunwoo Kim (@v4bel). Dirty Frag achieves root privileges on most Linux distributions. It does this by chaining two distinct high-severity vulnerabilities disclosed on 7 May 2026: the xfrm-ESP Page-Cache Write vulnerability and the RxRPC Page-Cache Write vulnerability.

If you are familiar with older vulnerabilities like Dirty Pipe or Copy Fail, Dirty Frag operates in a similar territory. However, while Dirty Pipe overwrites struct pipe_buffer, Dirty Frag specifically overwrites the frag (fragment) of a network buffer known as struct sk_buff.

To truly grasp how Dirty Frag works, we first need to break down a few core Linux kernel concepts that the write-up touches upon [1].

Core Concepts: The Building Blocks of the Dirty Frag

Before diving into the vulnerabilities themselves, let's clarify the mechanisms the attacker abuses:

The Page Cache

When Linux reads a file from disk, it stores a copy of that file's data in RAM, known as the page cache. This makes future reads significantly faster.

If an attacker can manipulate the page cache for a file they only have read access to (like /etc/passwd), any program that subsequently reads that file will see the attacker's modified version instead of the real file on disk.

splice() and Zero-Copy:

splice() is a system call that moves data between two file descriptors without copying it into user-space RAM. This is called "zero-copy".

When splice() is used on a file, it can take a reference (a pointer) to the file's page cache and pass it directly to another subsystem, such as the network stack.

sk_buff and Frags

In the Linux networking stack, a sk_buff (socket buffer) is the fundamental data structure used to hold network packets.

A packet might not be stored in a single contiguous block of memory. The sk_buff has a "linear" data area and can also point to additional chunks of memory called fragments, or frags.

In-Place Cryptography

When the kernel needs to decrypt a network packet, it can either copy the ciphertext to a new buffer and write the plaintext there, or it can decrypt the data "in-place," meaning it overwrites the original ciphertext with the decrypted plaintext directly in the same memory location.

How Dirty Frag Exploit Works?

In a zero-copy send path, an attacker uses splice() to plant a reference to a read-only page cache page directly into the frag slot of a sender-side sk_buff. When the receiver-side kernel code processes this packet, it mistakenly performs in-place cryptography directly on top of that frag.

Because the frag is actually a pointer to the read-only page cache of a critical file (like /etc/passwd or /usr/bin/su), the in-place cryptographic operation modifies the file's contents in RAM. Every subsequent read of that file sees the modified, attacker-controlled copy.

This exploit relies on two distinct vulnerabilities: CVE-2026-43284 (xfrm-ESP Page-Cache Write) and CVE-2026-43500 (RxRPC Page-Cache Write). Chaining them ensures the exploit functions reliably by covering each method's environmental blind spots across different Linux distributions.

For example, the ESP variant requires user namespace creation privileges, which Ubuntu often blocks, while the RxRPC variant relies on a kernel module that RHEL omits by default.

Let's look at the two specific vulnerabilities that make up this chain.

Vulnerability 1: CVE-2026-43284 (xfrm-ESP Page-Cache Write)

This vulnerability exists in the IPsec ESP (Encapsulating Security Payload) implementation.

When the Linux kernel receives an IPsec ESP (Encapsulating Security Payload) packet, it processes it through a function called esp_input(). Network packets can be "non-linear," meaning their data is split across multiple memory fragments (frags) rather than sitting in one continuous block.

If an attacker uses the splice() system call to plant a read-only page cache page (like a chunk of /usr/bin/su) into one of these frags, the kernel must be careful not to modify it.

Normally, before decrypting this data, the kernel is supposed to allocate a fresh, private memory buffer using skb_cow_data() (Copy-on-Write) and copy the frag data into it. However, a specific logical flaw in esp_input() allows a bypassed path: if the sk_buff is not cloned and lacks a frag_list, the code skips the copy-on-write process [1]:

if (!skb_cloned(skb)) {
if (!skb_is_nonlinear(skb)) {
nfrags = 1;
goto skip_cow;
} else if (!skb_has_frag_list(skb)) {
nfrags = skb_shinfo(skb)->nr_frags;
nfrags++;
goto skip_cow;
}
}

This forces the kernel to perform the decryption "in-place", meaning it overwrites the attacker-provided, read-only page cache page.

Well, the question is “How can an attacker overwrite the page cache freely ?”

The answer is ESN (Extended Sequence Numbers). When the kernel uses the ESP + ESN + authencesn(...) combination, a function named crypto_authenc_esn_decrypt() prepares the data. During its preprocessing step, it tries to move the high-order 4 bytes of the sequence number to the very end of the destination memory buffer.

Because the source and destination are the exact same memory page (due to the bypassed Copy-on-Write step), this results in a direct 4-byte STORE (a memory write) onto the read-only page cache page.

Exploit of CVE-2026-43284

The attacker targets /usr/bin/su. They replace the first 192 bytes of the file with a custom root-shell ELF executable by making 48 separate 4-byte writes. Because /usr/bin/su has the setuid-root bit intact, executing it grants a root shell.

Vulnerability 2: CVE-2026-43500 (RxRPC Page-Cache Write)

This second vulnerability exists in the RxRPC protocol implementation.

During packet verification, rxkad_verify_packet_1() performs an in-place single-block decryption on the first 8 bytes of the packet payload using an Andrew File System (AFS) dedicated cipher called fcrypt. Just like the ESP variant, if the attacker pinned a page cache page into the frag via splice, those 8 bytes are written directly into the page cache.

Unlike the ESP variant, where the attacker specifies the exact bytes, the value written here is the result of fcrypt_decrypt(C, K), where C is the original file data, and K is an attacker-controlled session key.

To write specific bytes, the attacker must port the deterministic fcrypt cipher to user-space and brute-force the key K until the decryption results in the desired plaintext.

Exploit of CVE-2026-43500

Because brute-forcing large amounts of data is computationally infeasible, the attacker targets a very small change. They target the root entry in /etc/passwd. By strategically modifying 12 bytes using three overlapping 8-byte writes, they overwrite the password field with an empty string.

A normal root entry looks like this: root:x:0:0:root:/root:/bin/bash

The x indicates that the password is required and securely stored elsewhere. The attacker's goal is to overwrite that section to look like this: root::0:0:GGGGGG:/root:/bin/bash

By removing the x and turning the password field into an empty string (::), the system's authentication module will accept a blank password and grant a root shell without prompting the user.

How to Remediate the Dirty Frag Vulnerability?

You can apply this mitigation by running the following command [1]:

sh -c "printf 'install esp4 /bin/false\ninstall esp6 /bin/false\ninstall rxrpc /bin/false\n' > /etc/modprobe.d/dirtyfrag.conf; rmmod esp4 esp6 rxrpc 2>/dev/null; echo 3 > /proc/sys/vm/drop_caches; true"

This is a temporary measure. Once your Linux distribution releases an update that backports the official kernel patches, you should update your system accordingly.

How Picus Simulates Dirty Frag Vulnerability Attacks?

We also strongly suggest simulating Dirty Frag vulnerability attacks to test the effectiveness of your security controls against real-life cyber attacks using the Picus Security Validation Platform. You can also test your defenses against other vulnerability exploitation attacks, such as regreSSHion, Citrix Bleed, and Follina, within minutes with a 14-day free trial of the Picus Platform.

Picus Threat Library includes the following threats for the Dirty Frag vulnerability attacks:

Threat ID

Threat Name

Attack Module

47837

Linux Kernel Dirty Frag Elevation of Privilege Vulnerability

Network Infiltration

55684

Linux Kernel Dirty Frag Elevation of Privilege Vulnerability

E-mail Infiltration

Start simulating emerging threats today and get actionable mitigation insights with a 14-day free trial of the Picus Security Validation Platform.

References

[1] “dirtyfrag/assets/write-up.md at master · V4bel/dirtyfrag,” GitHub. Accessed: May 18, 2026. [Online]. Available: https://github.com/V4bel/dirtyfrag/blob/master/assets/write-up.md

 
Dirty Frag is a powerful Linux kernel vulnerability class that allows an attacker to gain root privileges on most Linux distributions. It chains two distinct vulnerabilities: the xfrm-ESP Page-Cache Write (CVE-2026-43284) and the RxRPC Page-Cache Write (CVE-2026-43500). It operates similarly to older vulnerabilities like Dirty Pipe, but targets the frag of a network buffer instead of struct pipe_buffer.
CVE-2026-43284 is a flaw in the Linux kernel's IPsec ESP implementation. A logical error in esp_input() allows the kernel to skip the Copy-on-Write process and decrypt data in-place on a read-only page cache page. Using ESP with ESN and authencesn, an attacker makes 48 separate 4-byte writes to replace the first 192 bytes of /usr/bin/su with a custom root-shell ELF executable.
CVE-2026-43500 exists in the RxRPC protocol implementation. During packet verification, rxkad_verify_packet_1() performs in-place decryption using the fcrypt cipher, writing 8 bytes directly into the page cache. Unlike the ESP variant, where the attacker controls exact bytes, here the attacker must brute-force a session key in user-space until fcrypt decryption produces the desired plaintext output.
CVE-2026-43500 targets the root entry in /etc/passwd. Using three overlapping 8-byte writes, the attacker modifies 12 bytes to replace the password field indicator "x" with an empty string. This causes the system's authentication module to accept a blank password for the root account, granting a root shell without any password prompt.
Apply an immediate workaround, then patch. First, blacklist the vulnerable esp4, esp6, and rxrpc modules by pointing their installation to /bin/false. Next, unload them if active. Critically, flush the system's page cache to clear malicious memory modifications. Finally, install your Linux distribution's official kernel update once backported.
Picus Security Validation Platform includes dedicated Dirty Frag threats in the Picus Threat Library, covering both Network Infiltration (Threat ID 47837) and E-mail Infiltration (Threat ID 55684) attack modules. Organizations can simulate Dirty Frag exploitation alongside other attacks such as regreSSHion, Citrix Bleed, and Follina to test security controls and receive actionable mitigation insights.

Table of Contents

Ready to start? Request a demo