Skip to content

dirtyfrag security error in kernel (Like "Copy Fail") #40462

@RageGen

Description

@RageGen

Windows Version

Microsoft Windows [Version 10.0.26200.8246]

WSL Version

WSL version: 2.6.3.0

Are you using WSL 1 or WSL 2?

  • WSL 2
  • WSL 1

Kernel Version

Kernel version: 6.6.87.2-1

Distro Version

Ubuntu 24.04, 26.04

Other Software

No response

Repro Steps

Security error, same as CVE-2026-31431

Allows you to get root access on a local machine. The error comes from an unpatched Kernel module's - xfrm-ESP and RxRPC.

The code is publicly available in projects:

  1. https://github.com/V4bel/dirtyfrag
  2. https://github.com/0xdeadbeefnetwork/Copy_Fail2-Electric_Boogaloo

Steps:

  1. Run ./run.sh from second repo.

Expected Behavior

Error and no root access (with a rebuilt kernel without an error module, the exploit produces the expected result - on a standard WSL kernel, no).

Image

Actual Behavior

I'm getting root access.

Image

Diagnostic Logs

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions