CVE-2026-43503, Linux kernel "DirtyClone": page-cache corruption via XFRM/IPsec skb cloning (working PoC)
Defender actions
- Prioritise Linux kernel updates for DirtyClone (CVE-2026-43503) and pedit COW (CVE-2026-46331); until distro kernels ship, set
kernel.unprivileged_userns_clone=0(or blacklistact_pedit/esp4/esp6) where those features are unused. Treat unpatched multi-user/Kubernetes Linux hosts as locally privilege-escalatable for hunt purposes (§ 2, § 5). - On Debian/Ubuntu, set
kernel.unprivileged_userns_clone=0and blacklistesp4/esp6until DirtyClone (CVE-2026-43503) backports land, working root exploit confirmed (§ 4).
Analysis
JFrog Security Research published a full working-exploit walkthrough on 2026-06-25 for DirtyClone, the latest residual variant of the DirtyFrag family (JFrog Security Research, 2026-06-25). The flaw lives in __pskb_copy_fclone(), which fails to preserve the SKBFL_SHARED_FRAG safety flag when cloning a socket buffer; the cloned buffer, still referencing shared file-backed page-cache memory, is then passed through the XFRM/IPsec in-place decryption path, letting attacker-controlled bytes land in the cached image of a setuid binary such as /usr/bin/su (Red Hat, 2026-06-23). Earlier DirtyFrag fixes (CVE-2026-43284, CVE-2026-43500, CVE-2026-46300) do not close this code path; the fix is mainline commit 48f6a5356a33 (Linux v7.1-rc5, merged 2026-05-21), and most distributions had not yet shipped patched kernels at disclosure. The attack leaves no kernel-log or audit-trail artefacts.
Updates1
JFrog Security Research published a working-exploit write-up for CVE-2026-43503 (DirtyClone, CVSS 8.8), confirmed against Debian, Ubuntu, and Fedora (JFrog Security Research, 2026-06-25 · The Hacker News, 2026-06-29).
__pskb_copy_fclone() drops the SKBFL_SHARED_FRAG flag that marks memory as file-backed during packet cloning; an attacker with CAP_NET_ADMIN (reachable on Debian/Fedora via unprivileged user namespaces by default) wires a privileged binary's pages into a cloned packet, then routes it through an attacker-controlled IPsec tunnel so in-place decryption overwrites in-kernel login checks, granting root with no file-system trace. Mainline is fixed (commit since 2026-05-21); distribution backports are rolling. Until backports land: set kernel.unprivileged_userns_clone=0 on Debian/Ubuntu and blacklist the esp4/esp6 modules to remove the IPsec in-place-decryption primitive. Hunt namespace-creation events granting CAP_NET_ADMIN and su/sudo spawned from non-privileged parents without a TTY.
Sources3
Revision history
- Published 2026-06-27-40e791d4
- Update 2026-06-30-9aaa1114
UPDATE (originally covered 2026-06-27): JFrog Security Research published a working-exploit write-up for CVE-2026-43503 (DirtyClone, CVSS 8.8), confirmed against Debian, Ubuntu, and Fedora (JFrog Security Research, 2026-06-25 · The Hacker News, 2026-06-29).
Changed: actions sectors body
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.