
Lab detection exercise for DirtyFrag (CVE-2026-43284) - Linux kernel privilege escalation via xfrm-ESP page cache corruption. Full write-up covering exploit execution, detection gaps, and corrected EQL rules using Elastic Stack
Classification: Internal Lab - CyberLAB
Date: 24 May 2026
Platform: Elastic Stack v9.4.1
Status: Detection Confirmed
A controlled exploitation exercise simulating a post-initial-access adversary using DirtyFrag (CVE-2026-43284), a Linux kernel privilege escalation vulnerability. The simulated attacker scenario: low-privilege user (saskia, uid=1001) obtained via phished credentials attempts to escalate to root on an internal Linux host. The lab used a deliberately vulnerable Ubuntu machine (ubuntu-vuln, kernel 6.0.0-22-generic) isolated from production networks.
The attacker achieved full root access (uid=0) within the lab environment. The Elastic Security detection stack generated 3 HIGH-severity alerts (risk score 73) correctly identifying the exploitation chain. However, detection required manual tuning - the out-of-the-box configuration had gaps that would have resulted in missed alerts.
Bottom line: Unpatched Linux hosts running kernel <= 6.x are vulnerable. If an attacker already has a low-privilege foothold, this exploit gives them full root silently and quickly, with no on-disk trace visible to file integrity tools.
| Item | Detail |
|---|---|
| Vulnerability | DirtyFrag - CVE-2026-43284 (xfrm-ESP path), CVE-2026-43500 (RxRPC path) |
| CVSS impact | Full local privilege escalation to root |
| Affected kernels | Linux kernel >= January 2017 (9-year lifetime) |
| Affected distros | Ubuntu 24.04.4, RHEL 10.1, AlmaLinux 10, openSUSE, CentOS Stream 10, Fedora 44 |
| File integrity bypass | On-disk files unchanged - AIDE, Tripwire, hash monitoring all report clean |
| Public PoC | Available (V4bel/dirtyfrag on GitHub) |
| Time to root | < 10 minutes from low-privilege foothold |
auditd rules produce no evidence. Without explicit syscall rules for socket, splice, and unshare, the exploit runs silently - no logs, no alerts. Default Elastic Agent deployment does not add these rules automatically.process.parent.pid as the correlation key. In practice, DirtyFrag forks intermediate processes, breaking that correlation. The fix - correlating by auditd.session - was identified and implemented during this exercise./etc/shadow, accessed SSH authorized keys, wrote a persistence marker (/root/pwned.txt), and initiated network reconnaissance via nc. All occurred within 30 minutes of initial access.| Priority | Action |
|---|---|
| Immediate | Patch Linux kernel to a fixed version on all hosts. Apply vendor security advisories for Ubuntu, RHEL, AlmaLinux, openSUSE, CentOS, Fedora. |
| Short-term | Deploy explicit auditd syscall rules for socket, splice, and unshare on all Linux hosts monitored by Elastic Agent. |
| Short-term | Update EQL detection rules to correlate by auditd.session rather than process.parent.pid for namespace-manipulation sequences. |
| Ongoing | Treat privilege escalation alerts with risk score >= 73 as high-priority triage. Current rule fires within seconds of escalation. |
Objective: Validate detection coverage for DirtyFrag exploitation in the home lab SOC, identify detection gaps, and produce a corrected detection rule grounded in observed attacker behaviour.
Threat model: Simulated post-initial-access adversary with phished credentials for a low-privilege user account (saskia, uid=1001). Goal: privilege escalation to root via DirtyFrag using the xfrm-ESP receive path. Lab execution performed via Proxmox console - functionally equivalent to SSH post-access.
Two attacker capability tiers were considered:
This exercise covered the vanilla tier.
DirtyFrag is the third in a family of related Linux kernel bugs that all abuse the same root cause:
| CVE | Nickname | Introduced | Path |
|---|---|---|---|
| CVE-2022-0847 | Dirty Pipe | - | pipe |
| CVE-2026-31431 | Copy Fail | - | splice |
| CVE-2026-43284 | DirtyFrag | Jan 2017 (commit cac2661c53f3) | xfrm-ESP |
| CVE-2026-43500 | DirtyFrag | Jun 2023 (commit 2dc334f1a63a) | RxRPC |
Root cause: IPv4/IPv6 datagram append paths did not set SKBFL_SHARED_FRAG after skb_splice_from_iter() planted a page cache page into a socket buffer (sk_buff). The ESP input path then performed in-place crypto on attacker-controlled page cache pages, treating them as ordinary uncloned non-linear skbs.
Exploit primitive: 4 or 8-byte controlled write into the page cache. Deterministic - no race condition required.
Exploit chain:
/usr/bin/su) into page cachesplice() so the file's page sits in frag[0] of struct sk_buffxfrm-ESP decrypt pathexecve() - return corrupted bytesCritical evasion property: The on-disk file is never modified. File integrity monitoring tools (AIDE, Tripwire, hash checks) all report the target file as clean.
Confirmed vulnerable distributions: Ubuntu 24.04.4, RHEL 10.1, AlmaLinux 10, openSUSE Tumbleweed, CentOS Stream 10, Fedora 44.
| Component | Details |
|---|---|
| Fleet Server / ELK host | ubuntu-tm / elk-docker - 172.66.66.30 (lab-internal) |
| Elastic Stack | v9.4.1 (Elasticsearch, Kibana, Logstash - Docker) |
| Target (victim) host | ubuntu-vuln - 172.66.66.27 |
| Victim kernel | 6.0.0-22-generic (vulnerable) |
| Victim user | saskia - uid=1001, groups=1001(saskia),27(sudo),100(users) |
| Elastic Agent | v9.4.1 with auditbeat |
| Network IDS | Suricata 8.0.5 on dedicated sensor |
| Kibana | http://172.66.66.30:5601 (lab-internal) |
Active telemetry at exercise time:
| Dataset | Share |
|---|---|
suricata.eve | 75.2% |
elastic_agent.fleet_server | 10.8% |
elastic_agent | 9.1% |
elastic_agent.filebeat | 1.9% |
elastic_agent.auditbeat | 1.4% |
auditd_manager.auditd | 0.5% |
system.auth | 0.2% |
system.syslog | 0.1% |
Lab network isolated before exercise. Firewall alias Cyber_escape_door confirmed disabled - preventing lateral reach to other VLANs or internet.