TGViewer
Ralf Hacker Channel Ralf Hacker Channel @ralfhackerchannel · 28.3K subscribers
Post #1681 12.7K

Forwarded from APT

DirtyClone — CVE-2026-43503

A Linux kernel local privilege escalation and page-cache write. DirtyClone is the fourth public member of the DirtyPipe / DirtyFrag family: it forces the kernel to run an in-place ESP (IPsec) decrypt over a file-backed page-cache page the attacker only has read access to, mutating that page in RAM. With the AES-CBC key/IV chosen so the decrypt writes attacker-controlled bytes, /usr/bin/su is rewritten with a tiny setuid(0)+execve("/bin/sh") ELF and invoking it yields root.

🔗 Research:
https://research.jfrog.com/post/dissecting-and-exploiting-linux-lpe-variant-dirtyclone-cve-2026-43503/

🔗 Exploit:
https://github.com/rafaeldtinoco/security/tree/main/exploits/dirtyclone

#linux #lpe #kernel #dirty
  • 🔥 28
  • 👍 6
  • 🥰 1
More from @ralfhackerchannel
  1. Sep 18, 2026cups2root Linux LPE Interactive root shell from a local account in the lpadmin group.
  2. Sep 8, 2026Продолжается https://github.com/MSNightmare/ShieldCrash Windows Defender 0day Vulnerabilit…
  3. Sep 3, 2026Идем дальше https://github.com/MSNightmare/FalconFlank Crowdstrike Falcon 0day LPE #lpe #a…
  4. Aug 13, 2026VHDVomit A tool to search SMB shares for VHD/VMDK/VHDX backup files, mount them and dump s…
  5. Aug 11, 2026Он опять это сделал) https://github.com/MSNightmare/ShieldBreak Windows Defender LPE 0day…
  6. Jul 24, 2026🔒 Certighost (CVE-2026-54121) — AD CS Domain Controller Impersonation Low-privileged doma…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →