logo

New Fragnesia Linux flaw lets attackers gain root privileges

ID: 34931808-2b6f-5b8f-9f70-0f1b6ea93647

STIX ID: report--34931808-2b6f-5b8f-9f70-0f1b6ea93647

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: Sergiu Gatlan

...
...

Linux distributions are rolling out patches for a high-severity kernel local privilege escalation vulnerability named Fragnasia (CVE-2026-46300), part of the Dirty Frag class, which leverages a logic bug in the XFRM ESP-in-TCP subsystem to write arbitrary bytes into the kernel page cache of read-only files and attain root; a public PoC exists and vendors recommend applying kernel updates or removing vulnerable modules (rmmod esp4 esp6 rxrpc and blocking module loads) as a temporary mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.