Dirty Frag (CVE-2026-43284 / CVE-2026-43500): One Bug Class, Two New Sinks, One Patch Missing
Note: All testing described in this post was conducted on systems we own. The exploit code referenced is publicly disclosed by the original researcher Hyunwoo Kim (@v4bel) at github.com/V4bel/dirtyfrag, after the disclosure embargo was broken by an unrelated third party. The embargo, the quiet window between a