Fragnesia: New Linux kernel LPE bug was spawned by Dirty Frag patch (CVE-2026-46300)
ID: c5167d0b-d8df-533e-9586-1bb97f3379d3
STIX ID: report--c5167d0b-d8df-533e-9586-1bb97f3379d3
Feed Name: Help Net Security
**Fragnesia (CVE-2026-46300):** A newly disclosed Linux kernel local privilege escalation affecting the xfrm-ESP module that permits unprivileged attackers to deterministically corrupt the kernel page cache and gain root. The issue was discovered by Zellic.io, PoC exploit code and technical details have been published, and mitigations include vendor kernel patches and unloading/denylisting affected modules (esp4, esp6, rxrpc) with recommendations to drop the page cache after mitigation; there is currently no evidence of in-the-wild exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
