Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Dirty-Frag-CVE-2026-43284 — Lab detection exercise for DirtyFrag (CVE-2026-43284) - Linux kernel privilege escalation via xfrm-ESP page cache corruption. Full write-up covering exploit execution, detection gaps, and corrected EQL rules using Elastic Stack | Kitploit
Tools/GitHubGitHub/atlasvector/dirty-frag-cve-2026-43284
Privilege EscalationVulnerability AnalysisForensicsLearning & EducationIncident ResponseBinary ExploitationLabs & Practice
GitHubatlasvector/dirty-frag-cve-2026-43284

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Dirty-Frag-CVE-2026-43284

Lab detection exercise for DirtyFrag (CVE-2026-43284) - Linux kernel privilege escalation via xfrm-ESP page cache corruption. Full write-up covering exploit execution, detection gaps, and corrected EQL rules using Elastic Stack

View Repository
114 months agoNot yet reviewed

DirtyFrag (CVE-2026-43284) - Lab Detection Exercise Report

Classification: Internal Lab - CyberLAB
Date: 24 May 2026
Platform: Elastic Stack v9.4.1
Status: Detection Confirmed


Table of Contents

  • A - Executive Summary
  • B - Full Findings Report
    • 1. Objective and Threat Model
    • 2. Vulnerability Background
    • 3. Lab Environment
    • 4. Phase 1 - Pre-Execution Setup
    • 5. Phase 2 - Exploit Execution
    • 6. Phase 3 - Post-Exploitation Activity
    • 7. Phase 4 - Detection Engineering
    • 8. Detection Reference
    • 9. Key Findings Summary
    • 10. References

A - Executive Summary

What Was Tested

A controlled exploitation exercise simulating a post-initial-access adversary using DirtyFrag (CVE-2026-43284), a Linux kernel privilege escalation vulnerability. The simulated attacker scenario: low-privilege user (saskia, uid=1001) obtained via phished credentials attempts to escalate to root on an internal Linux host. The lab used a deliberately vulnerable Ubuntu machine (ubuntu-vuln, kernel 6.0.0-22-generic) isolated from production networks.

Result: Exploitation Succeeded - Detection Confirmed

The attacker achieved full root access (uid=0) within the lab environment. The Elastic Security detection stack generated 3 HIGH-severity alerts (risk score 73) correctly identifying the exploitation chain. However, detection required manual tuning - the out-of-the-box configuration had gaps that would have resulted in missed alerts.

Bottom line: Unpatched Linux hosts running kernel <= 6.x are vulnerable. If an attacker already has a low-privilege foothold, this exploit gives them full root silently and quickly, with no on-disk trace visible to file integrity tools.

Risk Statement

ItemDetail
VulnerabilityDirtyFrag - CVE-2026-43284 (xfrm-ESP path), CVE-2026-43500 (RxRPC path)
CVSS impactFull local privilege escalation to root
Affected kernelsLinux kernel >= January 2017 (9-year lifetime)
Affected distrosUbuntu 24.04.4, RHEL 10.1, AlmaLinux 10, openSUSE, CentOS Stream 10, Fedora 44
File integrity bypassOn-disk files unchanged - AIDE, Tripwire, hash monitoring all report clean
Public PoCAvailable (V4bel/dirtyfrag on GitHub)
Time to root< 10 minutes from low-privilege foothold

Key Findings

  1. Default auditd rules produce no evidence. Without explicit syscall rules for socket, splice, and unshare, the exploit runs silently - no logs, no alerts. Default Elastic Agent deployment does not add these rules automatically.
  2. Detection required rule tuning. The published Elastic Security Labs detection logic used process.parent.pid as the correlation key. In practice, DirtyFrag forks intermediate processes, breaking that correlation. The fix - correlating by auditd.session - was identified and implemented during this exercise.
  3. Post-exploitation actions were extensive. After gaining root, the attacker read /etc/shadow, accessed SSH authorized keys, wrote a persistence marker (/root/pwned.txt), and initiated network reconnaissance via nc. All occurred within 30 minutes of initial access.

Recommendations

PriorityAction
ImmediatePatch Linux kernel to a fixed version on all hosts. Apply vendor security advisories for Ubuntu, RHEL, AlmaLinux, openSUSE, CentOS, Fedora.
Short-termDeploy explicit auditd syscall rules for socket, splice, and unshare on all Linux hosts monitored by Elastic Agent.
Short-termUpdate EQL detection rules to correlate by auditd.session rather than process.parent.pid for namespace-manipulation sequences.
OngoingTreat privilege escalation alerts with risk score >= 73 as high-priority triage. Current rule fires within seconds of escalation.

B - Full Findings Report

1. Objective and Threat Model

Objective: Validate detection coverage for DirtyFrag exploitation in the home lab SOC, identify detection gaps, and produce a corrected detection rule grounded in observed attacker behaviour.

Threat model: Simulated post-initial-access adversary with phished credentials for a low-privilege user account (saskia, uid=1001). Goal: privilege escalation to root via DirtyFrag using the xfrm-ESP receive path. Lab execution performed via Proxmox console - functionally equivalent to SSH post-access.

Two attacker capability tiers were considered:

  • Vanilla (noisy): exploit run without any evasion
  • Evasive (quiet): reduced noise, deliberate cleanup

This exercise covered the vanilla tier.


2. Vulnerability Background

DirtyFrag is the third in a family of related Linux kernel bugs that all abuse the same root cause:

CVENicknameIntroducedPath
CVE-2022-0847Dirty Pipe-pipe
CVE-2026-31431Copy Fail-splice
CVE-2026-43284DirtyFragJan 2017 (commit cac2661c53f3)xfrm-ESP
CVE-2026-43500DirtyFragJun 2023 (commit 2dc334f1a63a)RxRPC

Root cause: IPv4/IPv6 datagram append paths did not set SKBFL_SHARED_FRAG after skb_splice_from_iter() planted a page cache page into a socket buffer (sk_buff). The ESP input path then performed in-place crypto on attacker-controlled page cache pages, treating them as ordinary uncloned non-linear skbs.

Exploit primitive: 4 or 8-byte controlled write into the page cache. Deterministic - no race condition required.

Exploit chain:

  1. Attacker reads target binary (e.g. /usr/bin/su) into page cache
  2. Constructs a packet via splice() so the file's page sits in frag[0] of struct sk_buff
  3. Kernel delivers packet to xfrm-ESP decrypt path
  4. ESP performs in-place crypto - source and destination both point at attacker's page
  5. Crypto writes attacker-controlled bytes into page cache
  6. All subsequent reads of the file - including kernel execve() - return corrupted bytes

Critical evasion property: The on-disk file is never modified. File integrity monitoring tools (AIDE, Tripwire, hash checks) all report the target file as clean.

Confirmed vulnerable distributions: Ubuntu 24.04.4, RHEL 10.1, AlmaLinux 10, openSUSE Tumbleweed, CentOS Stream 10, Fedora 44.


3. Lab Environment

ComponentDetails
Fleet Server / ELK hostubuntu-tm / elk-docker - 172.66.66.30 (lab-internal)
Elastic Stackv9.4.1 (Elasticsearch, Kibana, Logstash - Docker)
Target (victim) hostubuntu-vuln - 172.66.66.27
Victim kernel6.0.0-22-generic (vulnerable)
Victim usersaskia - uid=1001, groups=1001(saskia),27(sudo),100(users)
Elastic Agentv9.4.1 with auditbeat
Network IDSSuricata 8.0.5 on dedicated sensor
Kibanahttp://172.66.66.30:5601 (lab-internal)

Active telemetry at exercise time:

DatasetShare
suricata.eve75.2%
elastic_agent.fleet_server10.8%
elastic_agent9.1%
elastic_agent.filebeat1.9%
elastic_agent.auditbeat1.4%
auditd_manager.auditd0.5%
system.auth0.2%
system.syslog0.1%

4. Phase 1 - Pre-Execution Setup

4.1 Lab Isolation

Lab network isolated before exercise. Firewall alias Cyber_escape_door confirmed disabled - preventing lateral reach to other VLANs or internet.

Download Tool