▲ 59 ▼ Dirty Frag: Universal Linux LPE - allows any unprivileged local user to gain root access on a vulnerable Linux system - no patch available (github.com) submitted 5 months ago by cm0002@europe.pub to c/linux@programming.dev 19 comments fedilink hide all child comments
[–] Sunspear@piefed.social 4 points 5 months ago (2 children) Another one? :/ permalink fedilink source hideshow 2 child comments replies: [–] Sunspear@piefed.social 6 points 5 months ago (1 child) 2026-05-07: Submitted detailed information about the vulnerability and the exploit to the linux-distros mailing list. The embargo was set to 5 days, with an agreement that if a third party publishes the exploit on the internet during the embargo period, the Dirty Frag exploit would be published publicly. 2026-05-07: Detailed information and the exploit for this vulnerability were published publicly by an unrelated third party, breaking the embargo. Well, that's reassuring - hopefully, since the patch for it is also described in the repo, distro maintainers can patch it quickly permalink fedilink source parent hideshow 1 child comment replies: [–] Ooops@feddit.org 2 points 4 months ago Update: Kernel 7.0.5 just released Fixes: cac2661c53f3 ("esp4: Avoid skb_cow_data whenever possible") Fixes: 03e2a30f6a27 ("esp6: Avoid skb_cow_data whenever possible") Fixes: 7da0dde68486 ("ip, udp: Support MSG_SPLICE_PAGES") Fixes: 6d8192bd69bb ("ip6, udp6: Support MSG_SPLICE_PAGES") permalink fedilink source parent
[–] Sunspear@piefed.social 6 points 5 months ago (1 child) 2026-05-07: Submitted detailed information about the vulnerability and the exploit to the linux-distros mailing list. The embargo was set to 5 days, with an agreement that if a third party publishes the exploit on the internet during the embargo period, the Dirty Frag exploit would be published publicly. 2026-05-07: Detailed information and the exploit for this vulnerability were published publicly by an unrelated third party, breaking the embargo. Well, that's reassuring - hopefully, since the patch for it is also described in the repo, distro maintainers can patch it quickly permalink fedilink source parent hideshow 1 child comment replies: [–] Ooops@feddit.org 2 points 4 months ago Update: Kernel 7.0.5 just released Fixes: cac2661c53f3 ("esp4: Avoid skb_cow_data whenever possible") Fixes: 03e2a30f6a27 ("esp6: Avoid skb_cow_data whenever possible") Fixes: 7da0dde68486 ("ip, udp: Support MSG_SPLICE_PAGES") Fixes: 6d8192bd69bb ("ip6, udp6: Support MSG_SPLICE_PAGES") permalink fedilink source parent
[–] Ooops@feddit.org 2 points 4 months ago Update: Kernel 7.0.5 just released Fixes: cac2661c53f3 ("esp4: Avoid skb_cow_data whenever possible") Fixes: 03e2a30f6a27 ("esp6: Avoid skb_cow_data whenever possible") Fixes: 7da0dde68486 ("ip, udp: Support MSG_SPLICE_PAGES") Fixes: 6d8192bd69bb ("ip6, udp6: Support MSG_SPLICE_PAGES") permalink fedilink source parent