CVE-2026-43284 "Dirty Frag" still present in raspberry pi kernel
Dear AlmaLinux community, the recently disclosed "Dirty Frag" exploit that was thankfully patched by the AlmaLinux team with impressive speed in the main kernels is still present in the `raspberrypi2-kernel4` package that is shipped with AlmaLinux for Raspberry Pi (https://repo.almalinux.org/almalinux/10/raspberrypi/images/). It can however easily be fixed as the upstream commit (https://github.com/raspberrypi/linux/commit/b54edf1e9a3fd3491bdcb82a21f8d213...) cleanly applies against the AlmaLinux raspberry pi kernel sources. I have quickly created a fedora copr repo (https://copr.fedorainfracloud.org/coprs/hambingen/raspberry-pi_kernel/) with the patched kernel for an example of how to secure your system. Please consider patching this CVE in the raspberry pi kernel (if this is not already in the works). Yours, Hambingen
participants (1)
-
hambingen@protonmail.com