dirty_frag_mitigation
- 一个用于缓解 Linux dirty frag 漏洞(CVE-2026-43500)的 Bash 脚本
- 适用于所有基于 Debian/Ubuntu Arch 的平台,即 Kali、ParrotSec、BlackArch
- 添加了 --check 参数,允许非 root 用户运行。同时增加了对 fragnesia 的支持,因为它与 dirtyfrag 共享相同的补丁表面。
使用示例:
ᐅ dirty_frag_fix.sh --check
[*] Checking dirtyfrag mitigation status (non-root check mode)...
[*] Config file: /etc/modprobe.d/dirtyfrag.conf
[*] install esp4 /bin/false: yes
[*] install esp6 /bin/false: yes
[*] install rxrpc /bin/false: yes
[*] Any vulnerable modules currently loaded: no
[+] Likely mitigated against dirtyfrag based on module blocklist and load state.
[*] Note: This same module-level mitigation also reduces fragnesia exposure on the same ESP/XFRM surface.
[*] Note: Fragnesia is a separate bug with its own patch, but shares mitigation surface with dirtyfrag.