DirtyFrag Linux Kernel LPE Exploit Analysis
Score: 9/10

DirtyFrag Linux Kernel LPE Exploit Analysis

DirtyFrag is a sophisticated Linux kernel Local Privilege Escalation toolkit that uses page cache corruption and RxRPC/AF_ALG abuse to gain root access.

Executive Summary

DirtyFrag (associated with RansomHub) is a weaponized exploitation toolkit targeting Linux systems, specifically identified on Ubuntu 22. It leverages a kernel vulnerability (CVE-2026-0526) related to page cache fragmentation and splice operations to achieve Local Privilege Escalation (LPE). The malware is highly engineered, featuring dual exploitation paths and automated post-exploitation tasks.

The attack chain involves creating isolated user and network namespaces to gain CAP_NET_RAW, followed by either a 'splice' abuse path or a complex RxRPC/AF_ALG cryptographic abuse path. A key innovation is its ability to perform 'stealth persistence' by patching the kernel page cache of sensitive files like /etc/passwd or /usr/bin/su without modifying the physical disk, rendering traditional file integrity monitoring ineffective.

This threat is of critical concern due to its AVX-512 accelerated cryptanalysis engine and high-performance kernel heap grooming techniques. It is designed for immediate impact, automatically exfiltrating shadow hashes and spawning interactive root shells once escalation is achieved.

Key Details

Threat Name

DirtyFrag

Affects

Linux Kernel, Ubuntu 22

Adversary

RansomHub

Malware/Tools

DirtyFrag

Report Score

9out of 10
Quality Score
Excellent
IOC Quality6
TTP Details10
Detection Guidance9
Enterprise Relevance10
Clarity & Structure9
Technical Depth10

Sources