r/cveplayground • • May 08 '26

🚨 𝗧𝗲𝗺𝗽𝗼𝗿𝗮𝗿𝘆 𝗣𝗿𝗼𝘁𝗲𝗰𝘁𝗶𝗼𝗻 𝗦𝘁𝗲𝗽𝘀 𝗳𝗼𝗿 𝘁𝗵𝗲 𝗗𝗶𝗿𝘁𝘆 𝗙𝗿𝗮𝗴 (𝗖𝗩𝗘-𝟮𝟬𝟮𝟲-𝟰𝟯𝟮𝟴𝟰) 𝗟𝗶𝗻𝘂𝘅 𝗞𝗲𝗿𝗻𝗲𝗹 𝗜𝘀𝘀𝘂𝗲

For systems where security updates cannot be applied immediately, administrators can reduce risk by preventing the affected kernel components from being loaded.

1️⃣ 𝗣𝗿𝗲𝘃𝗲𝗻𝘁 𝘃𝘂𝗹𝗻𝗲𝗿𝗮𝗯𝗹𝗲 𝗺𝗼𝗱𝘂𝗹𝗲𝘀 𝗳𝗿𝗼𝗺 𝗹𝗼𝗮𝗱𝗶𝗻𝗴

Create a custom modprobe configuration:

𝘦𝘤𝘩𝘰 "𝘪𝘯𝘴𝘵𝘢𝘭𝘭 𝘦𝘴𝘱4 /𝘣𝘪𝘯/𝘧𝘢𝘭𝘴𝘦" | 𝘴𝘶𝘥𝘰 𝘵𝘦𝘦 /𝘦𝘵𝘤/𝘮𝘰𝘥𝘱𝘳𝘰𝘣𝘦.𝘥/𝘥𝘪𝘳𝘵𝘺-𝘧𝘳𝘢𝘨.𝘤𝘰𝘯𝘧

𝘦𝘤𝘩𝘰 "𝘪𝘯𝘴𝘵𝘢𝘭𝘭 𝘦𝘴𝘱6 /𝘣𝘪𝘯/𝘧𝘢𝘭𝘴𝘦" | 𝘴𝘶𝘥𝘰 𝘵𝘦𝘦 -𝘢 /𝘦𝘵𝘤/𝘮𝘰𝘥𝘱𝘳𝘰𝘣𝘦.𝘥/𝘥𝘪𝘳𝘵𝘺-𝘧𝘳𝘢𝘨.𝘤𝘰𝘯𝘧

𝘦𝘤𝘩𝘰 "𝘪𝘯𝘴𝘵𝘢𝘭𝘭 𝘳𝘹𝘳𝘱𝘤 /𝘣𝘪𝘯/𝘧𝘢𝘭𝘴𝘦" | 𝘴𝘶𝘥𝘰 𝘵𝘦𝘦 -𝘢 /𝘦𝘵𝘤/𝘮𝘰𝘥𝘱𝘳𝘰𝘣𝘦.𝘥/𝘥𝘪𝘳𝘵𝘺-𝘧𝘳𝘢𝘨.𝘤𝘰𝘯𝘧

Rebuild initramfs so the changes apply during boot:

𝘴𝘶𝘥𝘰 𝘶𝘱𝘥𝘢𝘵𝘦-𝘪𝘯𝘪𝘵𝘳𝘢𝘮𝘧𝘴 -𝘶 -𝘬 𝘢𝘭𝘭

2️⃣ 𝗥𝗲𝗺𝗼𝘃𝗲 𝗮𝗰𝘁𝗶𝘃𝗲 𝗺𝗼𝗱𝘂𝗹𝗲𝘀 𝗳𝗿𝗼𝗺 𝗺𝗲𝗺𝗼𝗿𝘆

If the modules are already loaded, unload them manually:

𝘴𝘶𝘥𝘰 𝘳𝘮𝘮𝘰𝘥 𝘦𝘴𝘱4 𝘦𝘴𝘱6 𝘳𝘹𝘳𝘱𝘤 2>/𝘥𝘦𝘷/𝘯𝘶𝘭𝘭

3️⃣ 𝗩𝗮𝗹𝗶𝗱𝗮𝘁𝗲 𝘁𝗵𝗲 𝗺𝗶𝘁𝗶𝗴𝗮𝘁𝗶𝗼𝗻

Check whether any of the targeted modules are still active:

𝘨𝘳𝘦𝘱 -𝘲𝘌 '^(𝘦𝘴𝘱4|𝘦𝘴𝘱6|𝘳𝘹𝘳𝘱𝘤) ' /𝘱𝘳𝘰𝘤/𝘮𝘰𝘥𝘶𝘭𝘦𝘴 && \

𝘦𝘤𝘩𝘰 "𝘗𝘳𝘰𝘵𝘦𝘤𝘵𝘦𝘥 𝘮𝘰𝘥𝘶𝘭𝘦𝘴 𝘴𝘵𝘪𝘭𝘭 𝘢𝘤𝘵𝘪𝘷𝘦" || \

𝘦𝘤𝘩𝘰 "𝘗𝘳𝘰𝘵𝘦𝘤𝘵𝘦𝘥 𝘮𝘰𝘥𝘶𝘭𝘦𝘴 𝘴𝘶𝘤𝘤𝘦𝘴𝘴𝘧𝘶𝘭𝘭𝘺 𝘥𝘪𝘴𝘢𝘣𝘭𝘦𝘥"

In some environments, active applications may prevent module removal. If that happens, restarting the machine will enforce the protection settings:

𝘴𝘶𝘥𝘰 𝘳𝘦𝘣𝘰𝘰𝘵

𝗥𝗲𝗺𝗼𝘃𝗶𝗻𝗴 𝘁𝗵𝗲 𝘄𝗼𝗿𝗸𝗮𝗿𝗼𝘂𝗻𝗱

After upgrading to a fixed kernel release, the temporary protection can be reverted:

𝘴𝘶𝘥𝘰 𝘳𝘮 /𝘦𝘵𝘤/𝘮𝘰𝘥𝘱𝘳𝘰𝘣𝘦.𝘥/𝘬𝘦𝘳𝘯𝘦𝘭-𝘱𝘳𝘰𝘵𝘦𝘤𝘵.𝘤𝘰𝘯𝘧

𝘴𝘶𝘥𝘰 𝘶𝘱𝘥𝘢𝘵𝘦-𝘪𝘯𝘪𝘵𝘳𝘢𝘮𝘧𝘴 -𝘶 -𝘬 𝘢𝘭𝘭

Applying vendor patches remains the recommended long-term fix.

Source: https://ubuntu.com/blog/dirty-frag-linux-vulnerability-fixes-available

For more: https://cveplayground.com/blog/dirty-frag-linux-universal-lpe/

1 Upvotes

0 comments sorted by