PoC Exploit Released for Fragnesia Linux Flaw Enabling Root Access
ID: 9de610e3-56ae-5700-9412-bf7b8268dd0a
STIX ID: report--9de610e3-56ae-5700-9412-bf7b8268dd0a
Feed Name: GBHackers
Threat Score
A newly disclosed Linux local privilege escalation vulnerability called "Fragnesia" abuses a logic error in the ESP/XFRM subsystem to write arbitrary data into the kernel page cache (similar to Dirty Pipe), enabling immediate root access. A public PoC targets /usr/bin/su, affects kernels prior to the May 13, 2026 patch, and the report includes mitigation steps (module removal/modprobe blacklisting, applying the kernel patch) and guidance to flush caches or reboot compromised systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
