logo

New Fragnesia Flaw Hands Linux Local Users Root Access

ID: dfb0ee23-ec9d-5d70-9aa3-f21dc134ce8e

STIX ID: report--dfb0ee23-ec9d-5d70-9aa3-f21dc134ce8e

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

...
...

A new Linux kernel local privilege escalation vulnerability, Fragnesia (CVE-2026-46300), allows unprivileged users to gain root by writing arbitrary bytes into the kernel page cache using an ESP-in-TCP decryption technique; a public PoC was published on May 13. The flaw is related to the Dirty Frag family, affects kernels released before the disclosure, and upstream fixes are pending while some distributions have started backporting patches; recommended interim mitigations include disabling esp4/esp6/rxrpc modules and restricting unprivileged user namespaces.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.