Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Dirty-Frag-Kubernetes-PoC — Proof-of-concept demonstrating container escape on Amazon EKS by exploiting Dirty Frag (CVE-2026-43284) kernel page-cache corruption via shared image layers and privileged DaemonSets. | Kitploit
Tools/GitHubGitHub/percivalll/dirty-frag-kubernetes-poc
Privilege EscalationVulnerability AnalysisExploitationCloud SecurityRed TeamingContainer Escape
GitHubpercivalll/dirty-frag-kubernetes-poc

Dirty-Frag-Kubernetes-PoC

Proof-of-concept demonstrating container escape on Amazon EKS by exploiting Dirty Frag (CVE-2026-43284) kernel page-cache corruption via shared image layers and privileged DaemonSets.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
16335 months agoNot yet reviewed

Dirty Frag (CVE-2026-43284) — Kubernetes Container Escape PoC

A proof-of-concept demonstrating how a default, unprivileged Kubernetes Pod can achieve node-level code execution on Amazon EKS by exploiting the Dirty Frag Linux kernel page-cache corruption vulnerability through shared container image layers.

The core attack primitive is: any privileged DaemonSet sharing image layers with an attacker-controlled container can be weaponized for container escape. This PoC uses kube-proxy as one concrete example, but the technique generalizes to any privileged workload on the cluster.

Validated on Amazon EKS (kernel 6.12.80) — an unprivileged pod writes [*] success to the host filesystem via the privileged kube-proxy DaemonSet:

EKS PoC

Disclaimer: This repository is published for educational and defensive purposes only. Use it exclusively on systems you own or have explicit authorization to test.

Background

Dirty Frag (CVE-2026-43284) is a Linux kernel page-cache corruption vulnerability in the xfrm/ESP receive path. In the affected path, esp_input() can skip skb_cow_data() for a non-linear skb without a frag_list, allowing crypto_authenc_esn_decrypt() to store 4 bytes of attacker-controlled data into a page-cache page reached through splice().

The file on disk is not modified. The corrupted bytes live in the kernel page cache and are observed by later readers of the same cached file page.

For full details on the original vulnerability, see V4bel/dirtyfrag.

Attack Principle

The attack exploits three properties that commonly coexist in Kubernetes clusters:

  1. Kernel page-cache corruption (CVE-2026-43284) — an unprivileged process (with user namespace support) can overwrite the in-memory cached pages of any file it can open read-only, via the xfrm/ESP splice race.
  2. Image layer sharing — container runtimes (containerd, CRI-O) use overlay filesystems where identical image layers map to the same page-cache pages across containers.
  3. Privileged DaemonSets — many clusters run DaemonSets with elevated privileges (privileged: true, hostNetwork: true, broad capabilities, etc.) that periodically execute binaries from their image.

When these conditions align, an unprivileged pod can corrupt a binary in a shared image layer, and a privileged DaemonSet on the same node will unknowingly execute the corrupted binary with its elevated privileges — achieving full node-level code execution.

The vulnerability target is NOT limited to kube-proxy. Any privileged DaemonSet (monitoring agents, CNI plugins, log collectors, security agents, etc.) whose container image shares layers with an attacker-controlled image is a viable target.

Difference from Copy Fail

This project is inspired by the Kubernetes exploitation model documented in the Copy Fail Kubernetes PoC, but uses a different kernel primitive.

PropertyCopy FailDirty Frag
CVECVE-2026-31431CVE-2026-43284
Kernel pathAF_ALG + splice()xfrm/ESP + splice()
Namespace requirementNot requiredRequires user namespaces
Main capability usedNone in the initial containerCAP_NET_ADMIN inside the new net namespace
Relevant modulealgif_aeadesp4
Practical distinctionBreaks if AF_ALG vector is blockedStill relevant when AF_ALG is unavailable but ESP/user namespaces are enabled

How It Works

The attack chain has three stages: page-cache corruption, cross-container propagation, and privileged execution.

1. Page-Cache Patching via xfrm/ESP

The PoC binary performs the following sequence from an unprivileged container:

  1. Enters new user and network namespaces with unshare(CLONE_NEWUSER | CLONE_NEWNET).
  2. Registers many xfrm Security Associations whose high sequence fields encode 4-byte payload chunks.
  3. Opens a target binary from the shared image layer read-only.
  4. Uses splice() and crafted ESP input to trigger the vulnerable kernel path.
  5. Repeats the primitive until the target binary's page-cache contents contain the embedded payload.

No write permission to the target file is required. The file on disk is unchanged — only the in-memory page cache is corrupted.

2. Cross-Container Propagation via Shared Layers

Container runtimes serve reads from overlay lower layers through the kernel page cache. If the PoC container and kube-proxy share the same lower-layer file, both observe the same cached pages.

The EKS image in this repository is built from:

public.ecr.aws/eks-distro-build-tooling/eks-distro-minimal-base-iptables:2026-03-11-1773190710.2023

That base is chosen to match the EKS kube-proxy userspace toolchain layer used in the validated environment.

3. Privileged Execution by kube-proxy

When kube-proxy next executes a patched iptables-family binary, the kernel loads the corrupted cached pages. The PoC payload mounts the host root device and writes a marker file to /root/res.

The expected marker content is:

[*] success

Attack Flow Diagram

┌──────────────────────────────┐     ┌────────────────────────┐     ┌──────────────────────────┐
│  PoC Pod                     │     │  Kernel Page Cache     │     │  kube-proxy DaemonSet    │
│  unprivileged container      │     │                        │     │  privileged container    │
│                              │     │                        │     │                          │
│  1. unshare user+net ns      │     │                        │     │                          │
│  2. install xfrm SAs         │     │                        │     │                          │
│  3. splice target binary     │────▶│  shared-layer binary   │────▶│  executes patched binary │
│     through ESP path         │     │  page cache patched    │     │  payload runs with       │
│                              │     │                        │     │  node-level privileges   │
└──────────────────────────────┘     └────────────────────────┘     └──────────────────────────┘

Validated Environment

Amazon EKS

PropertyValue
PlatformAmazon Elastic Kubernetes Service (EKS)
Node Kernel6.12.80-106.156.amzn2023.x86_64
Patch StatePre-fix kernel, missing f4c50a4034e6
esp4 ModuleLoaded
User NamespacesEnabled (user.max_user_namespaces=15030)
SELinuxPermissive
SeccompUnconfined in the tested pod context
Target DaemonSetkube-proxy
Target Privilegesprivileged: true, hostNetwork: true
Proxy Modeiptables
Marker Path/root/res
Download Tool