logo

Fragnesia CVE-2026-46300: Linux Kernel LPE Vulnerability Explained

ID: 95275c1a-5892-5277-9c7a-c91791868a24

STIX ID: report--95275c1a-5892-5277-9c7a-c91791868a24

Feed Name: Resources-2

Threat Score
75/100

Date Published: 2026-05-21

Date Updated: 2026-07-22

Author: [email protected] (Umut Bayram)

...
...

Fragnesia (CVE-2026-46300) is a high-severity (CVSS 7.8) Linux kernel local privilege escalation in the XFRM ESP-in-TCP subsystem that lets an unprivileged local attacker reliably modify page-cache contents of read-only executables (e.g., /usr/bin/su) by triggering in-place AES-GCM decryption, enabling a persistent root shell without altering the on-disk file; the report describes the root cause, exploitation steps (namespace, AES-GCM SA with hard-coded key, splice-and-ULP trigger), impact, mitigation (kernel patch and module blacklisting), and simulation/testing options via Picus and PoC references.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.