验证
git clone https://github.com/V4bel/dirtyfrag.git && cd dirtyfrag && gcc -O0 -Wall -o exp exp.c -lutil && ./exp

1
SHIINASAMA 8h 20m ago
😨
|
2
xiaomushen 8h 18m ago
AI 时代,开源系统真的是危险,
|
3
cryptovae 7h 48m ago
看着就害怕
|
4
maocat 7h 43m ago
代码展现了作者对 Linux 内核网络栈、加密子系统、文件系统页面缓存的深刻理解,是一个教科书级别的高级漏洞利用实现
deepseek 的评价。 |
5
bill5500 7h 43m ago
又要忙起来了
|
6
wsseo 7h 37m ago
我的天
|
7
hefish 7h 30m ago
我擦,我最新的 debian 13 内核中招。。。
老的 debian12 最新内核,没事。。。。哈哈哈 |
8
netnr 7h 18m ago
解决了权限不足的问题 😀
|
9
Bronya 7h 13m ago
卧槽,前两天刚升级一遍防止 Copy Fail 的 CVE ,这又来了一个……
|
10
Lightbright 7h 9m ago linux 忘记密码 root 怎么办.jpg
|
11
zsh2517 7h 8m ago
@Bronya 这个不用升级,因为还没补丁 /doge
https://github.com/V4bel/dirtyfrag/blob/master/assets/write-up.md#disclosure-timeline 里面有提到,原本五天后才会公布,但是有第三方违反规则公开了详情,于是 dirtyfrag 官方也公开了 2026-05-07: Submitted detailed information about the vulnerability and the exploit to the linux-distros mailing list. The embargo was set to 5 days, with an agreement that if a third party publishes the exploit on the internet during the embargo period, the Dirty Frag exploit would be published publicly. 2026-05-07: Detailed information and the exploit for this vulnerability were published publicly by an unrelated third party, breaking the embargo. 2026-05-07: After obtaining agreement from distribution maintainers to fully disclose Dirty Frag, the entire Dirty Frag document was published. |
12
sNullp 7h 7m ago
目测突破不了 rootless container (比如 unprivileged LXC )的容器壁
|
13
chouvel 6h 34m ago
如果连 linux 都能找到这种漏洞,那 windows 是不是也有?
|
14
whoosy 6h 33m ago
这下不害怕忘记 root 密码了
|
15
deplives 6h 27m ago
忘了 root 密码怎么办.jpg
|
16
willygeek007 6h 25m ago
卧擦,debian13 试了下真的能提权。有点东西,虽然看不懂原理
|
17
ybz PRO 咋 android 发现不了这种
|
18
insert000 6h 14m ago
linuxmint 22.3 执行成功
|
19
elboble 5h 53m ago
rpi4 幸免
|
21
duchenpaul 5h 40m ago
这个终端是啥, 光标有点炫
|
24
kaleido 5h 32m ago
题外话,你这个 shell 的光标效果是咋实现的,提示符也简洁好看,可以分享下吗?
|
25
greatbody 5h 26m ago Android 要是也有这样的提权漏洞就好了,可恶的小米。
|
26
Akikiki 5h 25m ago
不要手贱在公司机器上执行。。。。
|
27
x86 5h 16m ago
debian12 失败
|
28
miyuki OP |
29
liam01 5h 6m ago
这个有没有病毒啊,想在公司的机子上测试一下
|
32
ingram22mb30 4h 17m ago via Android
|
33
AutumnVerse 4h 9m ago
牛逼,ubuntu24.04 复现成功
|
35
apples01 2h 59m ago
Fedora-KDE-Desktop-Live-44-1.7.x86_64 完美提权
|
36
shirakawatyu 26 mins ago
6.14 内核 ubuntu 24.04 复现成功,之前 copyfail 都没成功这个直接一发入魂
|
37
shiny PRO 很难想象,各国政府在过去手里握了多少 0-day 漏洞
|