Dirty Frag Explained

A week after Copy Fail, another Linux page-cache LPE: Dirty Frag. Two bugs (xfrm-ESP and RxRPC) each provide a write primitive into cached memory, with each vulnerability targeting different default configurations for full distro coverage. In this video I cover the messy disclosure, walk through the author's POC, and run both exploit paths on the HTB Snapped machine. I also show how to clean it up. Writeup: https://github.com/V4bel/dirtyfrag/bl... POC: https://github.com/V4bel/dirtyfrag oss-security disclosure: https://www.openwall.com/lists/oss-se... SiCk's response: https://www.openwall.com/lists/oss-se... HTB Snapped post: https://0xdf.gitlab.io/2026/04/01/htb... ☕ Buy Me A Coffee: https://www.buymeacoffee.com/0xdf [0:00] Intro [1:07] Disclosure [3:51] Exploit overview [5:44] POC Code [8:22] RxRPC Demo [11:48] Cleanup [13:05] Demo ESP [14:11] Conclusion #dirtyfrag #CVE-2026-43284 #CVE-2026-43500