Dirty Frag in the wild, Ubuntu kernel vulnerable. Any user can gain root

See the disclosure: GitHub - V4bel/dirtyfrag · GitHub
Since it’s now in the wild, no point in keeping it hidden. The Ubuntu team should push a blog post/announcement about this asap. It’s in the same realm as CopyFail.

Can’t believe there are no references to this around these parts yet..

3 Likes

We’re too busy mitigating :joy:

9 Likes

if you are using apparmor in full enforce mode the exploit wont be able to work.

best of luck Steve ..

Please provide detailed information because information on github says AppArmor is not sufficient.

https://ubuntu.com/blog/dirty-frag-linux-vulnerability-fixes-available

4 Likes

When is the new Linux Kernel 7.0.6 coming to Ubuntu 26.04? It was out on monday I understood.

1 Like

We now have “fragnesia”: https://www.openwall.com/lists/oss-security/2026/05/13/3

1 Like

I just received an update and noticed that the kernel was updated to version 6.8.0-117-generic. Does anyone know if this fixes the Dirty Frag and fragnesia vulnerabilities? Thanks.

Some resources that will be useful to people seeking answers:

@RealAct - the 6.8.0.117-generic changelog mentions addressing CVE-2026-31431

7 Likes

Is there any timeline on when these CVEs will be fully addressed in kernel updates? While a update has been released to address the original copy:fail issue, the others are still under evaluation 1-2 weeks after being addressed upstream. In the mean time I just installed a third kernel update for proxmox in as many weeks…

2 Likes