New Fragnesia Linux flaw lets attackers gain root privileges
ID: 34931808-2b6f-5b8f-9f70-0f1b6ea93647
STIX ID: report--34931808-2b6f-5b8f-9f70-0f1b6ea93647
Feed Name: Bleeping Computer
Linux distributions are rolling out patches for a high-severity kernel local privilege escalation vulnerability named Fragnasia (CVE-2026-46300), part of the Dirty Frag class, which leverages a logic bug in the XFRM ESP-in-TCP subsystem to write arbitrary bytes into the kernel page cache of read-only files and attain root; a public PoC exists and vendors recommend applying kernel updates or removing vulnerable modules (rmmod esp4 esp6 rxrpc and blocking module loads) as a temporary mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
