
Proof-of-concept demonstrating container escape on Amazon EKS by exploiting Dirty Frag (CVE-2026-43284) kernel page-cache corruption via shared image layers and privileged DaemonSets.
A proof-of-concept demonstrating how a default, unprivileged Kubernetes Pod can achieve node-level code execution on Amazon EKS by exploiting the Dirty Frag Linux kernel page-cache corruption vulnerability through shared container image layers.
The core attack primitive is: any privileged DaemonSet sharing image layers with an attacker-controlled container can be weaponized for container escape. This PoC uses kube-proxy as one concrete example, but the technique generalizes to any privileged workload on the cluster.
Validated on Amazon EKS (kernel 6.12.80) — an unprivileged pod writes [*] success to the host filesystem via the privileged kube-proxy DaemonSet:

Disclaimer: This repository is published for educational and defensive purposes only. Use it exclusively on systems you own or have explicit authorization to test.
Dirty Frag (CVE-2026-43284) is a Linux kernel page-cache corruption vulnerability in the xfrm/ESP receive path. In the affected path, esp_input() can skip skb_cow_data() for a non-linear skb without a frag_list, allowing crypto_authenc_esn_decrypt() to store 4 bytes of attacker-controlled data into a page-cache page reached through splice().
The file on disk is not modified. The corrupted bytes live in the kernel page cache and are observed by later readers of the same cached file page.
For full details on the original vulnerability, see V4bel/dirtyfrag.
The attack exploits three properties that commonly coexist in Kubernetes clusters:
privileged: true, hostNetwork: true, broad capabilities, etc.) that periodically execute binaries from their image.When these conditions align, an unprivileged pod can corrupt a binary in a shared image layer, and a privileged DaemonSet on the same node will unknowingly execute the corrupted binary with its elevated privileges — achieving full node-level code execution.
The vulnerability target is NOT limited to kube-proxy. Any privileged DaemonSet (monitoring agents, CNI plugins, log collectors, security agents, etc.) whose container image shares layers with an attacker-controlled image is a viable target.
This project is inspired by the Kubernetes exploitation model documented in the Copy Fail Kubernetes PoC, but uses a different kernel primitive.
| Property | Copy Fail | Dirty Frag |
|---|---|---|
| CVE | CVE-2026-31431 | CVE-2026-43284 |
| Kernel path | AF_ALG + splice() | xfrm/ESP + splice() |
| Namespace requirement | Not required | Requires user namespaces |
| Main capability used | None in the initial container | CAP_NET_ADMIN inside the new net namespace |
| Relevant module | algif_aead | esp4 |
| Practical distinction | Breaks if AF_ALG vector is blocked | Still relevant when AF_ALG is unavailable but ESP/user namespaces are enabled |
The attack chain has three stages: page-cache corruption, cross-container propagation, and privileged execution.
The PoC binary performs the following sequence from an unprivileged container:
unshare(CLONE_NEWUSER | CLONE_NEWNET).splice() and crafted ESP input to trigger the vulnerable kernel path.No write permission to the target file is required. The file on disk is unchanged — only the in-memory page cache is corrupted.
Container runtimes serve reads from overlay lower layers through the kernel page cache. If the PoC container and kube-proxy share the same lower-layer file, both observe the same cached pages.
The EKS image in this repository is built from:
public.ecr.aws/eks-distro-build-tooling/eks-distro-minimal-base-iptables:2026-03-11-1773190710.2023
That base is chosen to match the EKS kube-proxy userspace toolchain layer used in the validated environment.
When kube-proxy next executes a patched iptables-family binary, the kernel loads the corrupted cached pages. The PoC payload mounts the host root device and writes a marker file to /root/res.
The expected marker content is:
[*] success
┌──────────────────────────────┐ ┌────────────────────────┐ ┌──────────────────────────┐
│ PoC Pod │ │ Kernel Page Cache │ │ kube-proxy DaemonSet │
│ unprivileged container │ │ │ │ privileged container │
│ │ │ │ │ │
│ 1. unshare user+net ns │ │ │ │ │
│ 2. install xfrm SAs │ │ │ │ │
│ 3. splice target binary │────▶│ shared-layer binary │────▶│ executes patched binary │
│ through ESP path │ │ page cache patched │ │ payload runs with │
│ │ │ │ │ node-level privileges │
└──────────────────────────────┘ └────────────────────────┘ └──────────────────────────┘
| Property | Value |
|---|---|
| Platform | Amazon Elastic Kubernetes Service (EKS) |
| Node Kernel | 6.12.80-106.156.amzn2023.x86_64 |
| Patch State | Pre-fix kernel, missing f4c50a4034e6 |
esp4 Module | Loaded |
| User Namespaces | Enabled (user.max_user_namespaces=15030) |
| SELinux | Permissive |
| Seccomp | Unconfined in the tested pod context |
| Target DaemonSet | kube-proxy |
| Target Privileges | privileged: true, hostNetwork: true |
| Proxy Mode | iptables |
| Marker Path | /root/res |