A week after Copy Fail, researcher Hyunwoo Kim disclosed a second Linux kernel flaw in the same broad area — IPsec ESP and rxrpc — that they have named Dirty Frag. The bug lives in the in-place decryption fast paths of esp4, esp6, and rxrpc: when a socket buffer carries paged fragments that are not privately owned by the kernel (e.g. pipe pages attached via splice(2)/sendfile(2)/MSG_SPLICE_PAGES), the receive path decrypts directly over those externally-backed pages, exposing or corrupting plaintext that an unprivileged process still holds a reference to.
Like the previous Copy Fail vulnerability, Dirty Frag immediately yields root on all major distributions. Every supported Manjaro release is affected. Per Hyunwoo Kim’s public disclosure on oss-security (2026-05-07), the responsible-disclosure embargo was broken before distributions could coordinate, so no CVE identifiers have been allocated for either of the two bugs that make up Dirty Frag, and a working exploit is now publicly available.
More information about the vulnerability:
- Public disclosure on oss-security: oss-security - Dirty Frag: Universal Linux LPE
- Researcher write-up: https://dirtyfrag.io
- Upstream fix for ESP: Making sure you're not a bot!
- rxrpc fix on the netdev list: Making sure you're not a bot!
Temporary mitigation
You can neutralize the attack surface by blacklisting the affected modules. None of esp4, esp6, or rxrpc are loaded on a typical workload that does not use IPsec transport mode or AFS, so on most systems this is safe to apply immediately:
sudo sh -c "printf 'install esp4 /bin/false\ninstall esp6 /bin/false\ninstall rxrpc /bin/false\n' > /etc/modprobe.d/dirtyfrag.conf; rmmod esp4 esp6 rxrpc 2>/dev/null; true"
This writes a modprobe config that prevents the three modules from loading, and unloads them if they happen to be loaded already (the rmmod is best-effort and silent if the module isn’t present). To revert, remove /etc/modprobe.d/dirtyfrag.conf.
The Dirty Frag exploit works by corrupting page-cache pages of sensitive files (such as /etc/passwd or /usr/bin/su). If you suspect the system may have already been targeted before you applied the mitigation, drop the page cache so any tampered pages are evicted and the next read comes fresh from disk:
sudo sh -c 'echo 3 > /proc/sys/vm/drop_caches'
This is safe to run on a live system — it only frees clean cache and dentry/inode entries — and pairs well with the blacklist above.
Upcoming Fixes
We are currently building some kernels with early patches applied:
- [pkg-upd] 6.18.27-2 (0697d241) · Commits · Packages / core / linux618 · GitLab
- [pkg-upd] 7.0.4-2 (59260d18) · Commits · Packages / core / linux70 · GitLab
You may want to switch to unstable branch as soon as they hit our repos or get them directly from our Github pages:
All current kernels are vulnerable to this exploit, unless communicated otherwise!
1 post - 1 participant