Rajat Gupta

Read Access, Root Shell, Repeat: The Page-Cache Corruption Lineage

Abstract

Page-cache corruption bugs are unusual because they can turn read access into the ability to modify the in-memory contents of file-backed pages, enabling local privilege escalation without changing data on disk. After Dirty COW, Dirty Pipe, Copy Fail, Dirty Frag most variant hunting focused on

syntactic copies of known paths — grep for the function name, find the clone, move on.

We decompose the entire Dirty COW to Dirty Frag exploitation chain into three independently queryable stages — Entry, Violated Invariant, and Writer — and trace at the source level how each generation's patch addressed one stage while leaving the others wide open. That structural analysis, combined with a semantic variant-hunting methodology using targeted CodeQL queries with deterministic verification feedback, produced a focused campaign of 16 queries across the kernel and three new unprivileged root exploits: skb_shift and GRO flag loss (CVE-2026-43503) — both bypass previous patches through independent mechanisms in TCP SACK processing and GRO receive offload — and the flagship, Dirty Pedit (CVE-2026-46331), a previously unknown route to deterministic root
in under one second via Linux traffic control. Dirty Pedit emerged from intersecting results across independent query stages: one identified a signed-to-unsigned wraparound in skb_ensure_writable() creating a partial-COW gap, another surfaced tcf_pedit_act() as a novel writer primitive — a direct
4-byte page-cache write via skb_store_bits, no crypto subsystem required. Separately, they're curiosities. Together, they're root in under one second.

The talk includes source-level walkthrough of each exploit's three-stage anatomy, live demonstrations, and a structural argument for why this class will keep producing variants until the kernel enforces page-cache write invariants at the subsystem boundary rather than per-callsite. All findings responsibly disclosed; patches merged upstream.

BIO

Rajat Gupta finds and exploits vulnerabilities across browsers, Linux kernel, and Windows kernel drivers, and develops systems for systematic vulnerability discovery at scale. His variant analysis methodology turned one kernel root cause into three universal local privilege-escalation exploits. Previously, he built Popkorn with UCSB Shellphish — discovering four privilege-escalation vulnerabilities in Windows kernel drivers using targeted symbolic execution (ACSAC 2022), co-authored browser security research with Georgia Tech SSLab, and competed in DEF CON CTF Finals three years running. When not breaking kernels at Qualcomm, he's hunting perfect backhand loops at the table tennis table, trails with elevation gain, or the spiciest dish on the menu.