Fragnesia CVE-2026-46300: Linux Kernel LPE Vulnerability Explained
ID: 95275c1a-5892-5277-9c7a-c91791868a24
STIX ID: report--95275c1a-5892-5277-9c7a-c91791868a24
Feed Name: Resources-2
Fragnesia (CVE-2026-46300) is a high-severity (CVSS 7.8) Linux kernel local privilege escalation in the XFRM ESP-in-TCP subsystem that lets an unprivileged local attacker reliably modify page-cache contents of read-only executables (e.g., /usr/bin/su) by triggering in-place AES-GCM decryption, enabling a persistent root shell without altering the on-disk file; the report describes the root cause, exploitation steps (namespace, AES-GCM SA with hard-coded key, splice-and-ULP trigger), impact, mitigation (kernel patch and module blacklisting), and simulation/testing options via Picus and PoC references.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
