dirty_frag_mitigation
- Linux dirty frag エクスプロイト CVE-2026-43500 を緩和するための bash スクリプト
- すべての Debian/Ubuntu/Arch ベースのプラットフォーム(Kali, ParrotSec, BlackArch)で動作します
- 非 root ユーザーとして実行するための --check オプションを追加。dirtyfrag と同じパッチ領域を共有するため、fragnesia サポートを追加。
使用例:
ᐅ dirty_frag_fix.sh --check
[*] Checking dirtyfrag mitigation status (non-root check mode)...
[*] Config file: /etc/modprobe.d/dirtyfrag.conf
[*] install esp4 /bin/false: yes
[*] install esp6 /bin/false: yes
[*] install rxrpc /bin/false: yes
[*] Any vulnerable modules currently loaded: no
[+] Likely mitigated against dirtyfrag based on module blocklist and load state.
[*] Note: This same module-level mitigation also reduces fragnesia exposure on the same ESP/XFRM surface.
[*] Note: Fragnesia is a separate bug with its own patch, but shares mitigation surface with dirtyfrag.