Dirty Frag LPE: CVE-2026-43284 and CVE-2026-43500 Deep Dive
| May 20, 2026
Key Takeaways
- Dirty Frag is a Linux kernel vulnerability class that chains two bugs (CVE-2026-43284 and CVE-2026-43500) to achieve root privileges on most Linux distributions by writing attacker-controlled data directly into read-only page cache pages via in-place cryptographic operations.
- CVE-2026-43284 exploits a logic flaw in the IPsec ESP implementation that bypasses Copy-on-Write protections, enabling 48 separate 4-byte writes to overwrite the first 192 bytes of /usr/bin/su with a custom root-shell ELF executable.
- CVE-2026-43500 exploits the RxRPC protocol's in-place fcrypt decryption to modify 12 bytes of /etc/passwd, clearing the root password field so the system accepts a blank password and grants a root shell without authentication.
- The attack abuses the splice() system call's zero-copy mechanism to plant a reference to a read-only page cache page into an sk_buff frag, which the kernel then unknowingly overwrites during packet processing.
- Picus Threat Library includes dedicated Dirty Frag simulation threats, allowing organizations to validate their security controls against this vulnerability.
Recently, a powerful vulnerability class known as "Dirty Frag" was discovered and reported by Hyunwoo Kim (@v4bel). Dirty Frag achieves root privileges on most Linux distributions. It does this by chaining two distinct high-severity vulnerabilities disclosed on 7 May 2026: the xfrm-ESP Page-Cache Write vulnerability and the RxRPC Page-Cache Write vulnerability.
If you are familiar with older vulnerabilities like Dirty Pipe or Copy Fail, Dirty Frag operates in a similar territory. However, while Dirty Pipe overwrites struct pipe_buffer, Dirty Frag specifically overwrites the frag (fragment) of a network buffer known as struct sk_buff.
To truly grasp how Dirty Frag works, we first need to break down a few core Linux kernel concepts that the write-up touches upon [1].
Core Concepts: The Building Blocks of the Dirty Frag
Before diving into the vulnerabilities themselves, let's clarify the mechanisms the attacker abuses:
The Page Cache
When Linux reads a file from disk, it stores a copy of that file's data in RAM, known as the page cache. This makes future reads significantly faster.
If an attacker can manipulate the page cache for a file they only have read access to (like /etc/passwd), any program that subsequently reads that file will see the attacker's modified version instead of the real file on disk.
splice() and Zero-Copy:
splice() is a system call that moves data between two file descriptors without copying it into user-space RAM. This is called "zero-copy".
When splice() is used on a file, it can take a reference (a pointer) to the file's page cache and pass it directly to another subsystem, such as the network stack.
sk_buff and Frags
In the Linux networking stack, a sk_buff (socket buffer) is the fundamental data structure used to hold network packets.
A packet might not be stored in a single contiguous block of memory. The sk_buff has a "linear" data area and can also point to additional chunks of memory called fragments, or frags.
In-Place Cryptography
When the kernel needs to decrypt a network packet, it can either copy the ciphertext to a new buffer and write the plaintext there, or it can decrypt the data "in-place," meaning it overwrites the original ciphertext with the decrypted plaintext directly in the same memory location.
How Dirty Frag Exploit Works?
In a zero-copy send path, an attacker uses splice() to plant a reference to a read-only page cache page directly into the frag slot of a sender-side sk_buff. When the receiver-side kernel code processes this packet, it mistakenly performs in-place cryptography directly on top of that frag.
Because the frag is actually a pointer to the read-only page cache of a critical file (like /etc/passwd or /usr/bin/su), the in-place cryptographic operation modifies the file's contents in RAM. Every subsequent read of that file sees the modified, attacker-controlled copy.
This exploit relies on two distinct vulnerabilities: CVE-2026-43284 (xfrm-ESP Page-Cache Write) and CVE-2026-43500 (RxRPC Page-Cache Write). Chaining them ensures the exploit functions reliably by covering each method's environmental blind spots across different Linux distributions.
For example, the ESP variant requires user namespace creation privileges, which Ubuntu often blocks, while the RxRPC variant relies on a kernel module that RHEL omits by default.
Let's look at the two specific vulnerabilities that make up this chain.
Vulnerability 1: CVE-2026-43284 (xfrm-ESP Page-Cache Write)
This vulnerability exists in the IPsec ESP (Encapsulating Security Payload) implementation.
When the Linux kernel receives an IPsec ESP (Encapsulating Security Payload) packet, it processes it through a function called esp_input(). Network packets can be "non-linear," meaning their data is split across multiple memory fragments (frags) rather than sitting in one continuous block.
If an attacker uses the splice() system call to plant a read-only page cache page (like a chunk of /usr/bin/su) into one of these frags, the kernel must be careful not to modify it.
Normally, before decrypting this data, the kernel is supposed to allocate a fresh, private memory buffer using skb_cow_data() (Copy-on-Write) and copy the frag data into it. However, a specific logical flaw in esp_input() allows a bypassed path: if the sk_buff is not cloned and lacks a frag_list, the code skips the copy-on-write process [1]:
|
if (!skb_cloned(skb)) { |
This forces the kernel to perform the decryption "in-place", meaning it overwrites the attacker-provided, read-only page cache page.
Well, the question is “How can an attacker overwrite the page cache freely ?”
The answer is ESN (Extended Sequence Numbers). When the kernel uses the ESP + ESN + authencesn(...) combination, a function named crypto_authenc_esn_decrypt() prepares the data. During its preprocessing step, it tries to move the high-order 4 bytes of the sequence number to the very end of the destination memory buffer.
Because the source and destination are the exact same memory page (due to the bypassed Copy-on-Write step), this results in a direct 4-byte STORE (a memory write) onto the read-only page cache page.
Exploit of CVE-2026-43284
The attacker targets /usr/bin/su. They replace the first 192 bytes of the file with a custom root-shell ELF executable by making 48 separate 4-byte writes. Because /usr/bin/su has the setuid-root bit intact, executing it grants a root shell.
Vulnerability 2: CVE-2026-43500 (RxRPC Page-Cache Write)
This second vulnerability exists in the RxRPC protocol implementation.
During packet verification, rxkad_verify_packet_1() performs an in-place single-block decryption on the first 8 bytes of the packet payload using an Andrew File System (AFS) dedicated cipher called fcrypt. Just like the ESP variant, if the attacker pinned a page cache page into the frag via splice, those 8 bytes are written directly into the page cache.
Unlike the ESP variant, where the attacker specifies the exact bytes, the value written here is the result of fcrypt_decrypt(C, K), where C is the original file data, and K is an attacker-controlled session key.
To write specific bytes, the attacker must port the deterministic fcrypt cipher to user-space and brute-force the key K until the decryption results in the desired plaintext.
Exploit of CVE-2026-43500
Because brute-forcing large amounts of data is computationally infeasible, the attacker targets a very small change. They target the root entry in /etc/passwd. By strategically modifying 12 bytes using three overlapping 8-byte writes, they overwrite the password field with an empty string.
A normal root entry looks like this: root:x:0:0:root:/root:/bin/bash
The x indicates that the password is required and securely stored elsewhere. The attacker's goal is to overwrite that section to look like this: root::0:0:GGGGGG:/root:/bin/bash
By removing the x and turning the password field into an empty string (::), the system's authentication module will accept a blank password and grant a root shell without prompting the user.
How to Remediate the Dirty Frag Vulnerability?
You can apply this mitigation by running the following command [1]:
|
sh -c "printf 'install esp4 /bin/false\ninstall esp6 /bin/false\ninstall rxrpc /bin/false\n' > /etc/modprobe.d/dirtyfrag.conf; rmmod esp4 esp6 rxrpc 2>/dev/null; echo 3 > /proc/sys/vm/drop_caches; true" |
This is a temporary measure. Once your Linux distribution releases an update that backports the official kernel patches, you should update your system accordingly.
How Picus Simulates Dirty Frag Vulnerability Attacks?
We also strongly suggest simulating Dirty Frag vulnerability attacks to test the effectiveness of your security controls against real-life cyber attacks using the Picus Security Validation Platform. You can also test your defenses against other vulnerability exploitation attacks, such as regreSSHion, Citrix Bleed, and Follina, within minutes with a 14-day free trial of the Picus Platform.
Picus Threat Library includes the following threats for the Dirty Frag vulnerability attacks:
|
Threat ID |
Threat Name |
Attack Module |
|
47837 |
Linux Kernel Dirty Frag Elevation of Privilege Vulnerability |
Network Infiltration |
|
55684 |
Linux Kernel Dirty Frag Elevation of Privilege Vulnerability |
E-mail Infiltration |
Start simulating emerging threats today and get actionable mitigation insights with a 14-day free trial of the Picus Security Validation Platform.
References
[1] “dirtyfrag/assets/write-up.md at master · V4bel/dirtyfrag,” GitHub. Accessed: May 18, 2026. [Online]. Available: https://github.com/V4bel/dirtyfrag/blob/master/assets/write-up.md
