- -

Árbol de páginas

Versiones comparadas

Clave

  • Se ha añadido esta línea.
  • Se ha eliminado esta línea.
  • El formato se ha cambiado.

...

Se recuerda que parchear las máquinas de usuario no tiene efecto, ya que esos cambios se perderán cuando se vuelvan a regenerar de la master.

No es necesario reiniciar

...

, pero hay que borrar la page-caché

Si la mitigación se aplica DESPUÉS de que alguien haya ejecutado el exploit, éste sigue funcionando en memoria, y puede seguir siendo utilizado.

...

La información de la vulnerabilidad ha sido publicada inicialmente por un tercero antes de tiempo, rompiendo el embargo y sin margen para incluir los parches en las distribuciones.

  • 026-04-30: Submitted detailed information about the esp vulnerability and a weaponized exploit that achieves root privileges on several major distributions to security@kernel.org.
  • 2026-04-30: Submitted the patch for the esp vulnerability to the netdev mailing list. Information about this issue was published publicly.
  • 2026-04-30 (+9h): Kuan-Ting Chen submitted a vulnerability report for the esp vulnerability with a reproducer to security@kernel.org.
  • 2026-05-04: Kuan-Ting Chen submitted the shared-frag approach patch to the netdev mailing list.
  • 2026-05-07: The patch was merged into the netdev tree.
  • 2026-05-07: Submitted detailed information about the vulnerability and the exploit to the linux-distros mailing list. The embargo was set to 5 days, with an agreement that if a third party publishes the exploit on the internet during the embargo period, the Dirty Frag exploit would be published publicly.
  • 2026-05-07: Detailed information and the exploit for this vulnerability were published publicly by an unrelated third party, breaking the embargo.
  • 2026-05-07: After obtaining agreement from distribution maintainers to fully disclose Dirty Frag, the entire Dirty Frag document was published.

Fuente; https://github.com/V4bel/dirtyfrag/blob/master/assets/write-up.md#disclosure-timeline

...