Dirty Frag: Universal Linux LPE

(github.com)

8 points | by nahikoa 6 days ago ago

3 comments

  • undefined 6 days ago ago
    [deleted]
  • mehmetkeremmtl 6 days ago ago

    With a name like 'Dirty Frag', I'm guessing this is another memory fragmentation or page cache trick similar to Dirty Pipe?

    • TacticalCoder 6 days ago ago

      From TFA:

      > Dirty Frag belongs to the same class as Dirty Pipe and Copy Fail. However, while Dirty Pipe overwrites struct pipe_buffer, Dirty Frag overwrites the frag of struct sk_buff

      So yup, Dirty Pipe is specifically mentioned.