TGViewer
Fsecurity | HH Fsecurity | HH @hellohackingteam · 2.06K subscribers
Post #7799 116

Forwarded from APT

DirtyClone — CVE-2026-43503

A Linux kernel local privilege escalation and page-cache write. DirtyClone is the fourth public member of the DirtyPipe / DirtyFrag family: it forces the kernel to run an in-place ESP (IPsec) decrypt over a file-backed page-cache page the attacker only has read access to, mutating that page in RAM. With the AES-CBC key/IV chosen so the decrypt writes attacker-controlled bytes, /usr/bin/su is rewritten with a tiny setuid(0)+execve("/bin/sh") ELF and invoking it yields root.

🔗 Research:
https://research.jfrog.com/post/dissecting-and-exploiting-linux-lpe-variant-dirtyclone-cve-2026-43503/

🔗 Exploit:
https://github.com/rafaeldtinoco/security/tree/main/exploits/dirtyclone

#linux #lpe #kernel #dirty
More from @hellohackingteam
  1. Oct 8, 2026LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warning…
  2. Oct 8, 2026Чаще всего во время работ по анализу защищённости пробив периметра происходит через выполн…
  3. Oct 7, 2026Sliver GUI — это кроссплатформенное настольное приложение на базе Electron для Sliver. Оно…
  4. Oct 7, 2026🔗 Ссылка: https://fortbridge.co.uk/research/wordpress-libheif-rce/
  5. Oct 7, 2026CVE-2026-43783: Починить права — получить root: LPE через DesktopServicesHelper в macOS 26…
  6. Oct 6, 2026Браузер, построенный на ошибках: как атаки меняли его защиту Почему браузер устроен именно…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →