...
| Bloque de código |
|---|
sudo echo 3 > /proc/sys/vm/drop_caches |
Historial de la vulnerabilidad
La información de la vulnerabilidad ha sido publicada inicialmente por un tercero antes de tiempo, rompiendo el embargo y sin margen para incluir los parches en las distribuciones.
- 026-04-30: Submitted detailed information about the esp vulnerability and a weaponized exploit that achieves root privileges on several major distributions to security@kernel.org.
- 2026-04-30: Submitted the patch for the esp vulnerability to the netdev mailing list. Information about this issue was published publicly.
- 2026-04-30 (+9h): Kuan-Ting Chen submitted a vulnerability report for the esp vulnerability with a reproducer to security@kernel.org.
- 2026-05-04: Kuan-Ting Chen submitted the shared-frag approach patch to the netdev mailing list.
- 2026-05-07: The patch was merged into the netdev tree.
- 2026-05-07: Submitted detailed information about the vulnerability and the exploit to the linux-distros mailing list. The embargo was set to 5 days, with an agreement that if a third party publishes the exploit on the internet during the embargo period, the Dirty Frag exploit would be published publicly.
- 2026-05-07: Detailed information and the exploit for this vulnerability were published publicly by an unrelated third party, breaking the embargo.
- 2026-05-07: After obtaining agreement from distribution maintainers to fully disclose Dirty Frag, the entire Dirty Frag document was published.
Fuente; https://github.com/V4bel/dirtyfrag/blob/master/assets/write-up.md#disclosure-timeline
Otras fuentes de interés:
GitHub - V4bel/dirtyfrag · GitHub
...