logo

Fragnesia (CVE-2026-46300): Frequently asked questions about new Linux Kernel XFRM ESP-in-TCP privilege escalation

ID: 1fded54c-93ee-59ff-91b8-08cf94375aa6

STIX ID: report--1fded54c-93ee-59ff-91b8-08cf94375aa6

Feed Name: Security Boulevard

Threat Score
70/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: Satnam Narang

...
...

Tenable RSO documents Fragnesia (CVE-2026-46300), a high-severity Linux kernel XFRM ESP-in-TCP local privilege escalation disclosed May 13 with a public proof-of-concept; the flaw allows local users to gain root via page-cache writes, affects many mainstream distributions, has an estimated CVSSv3 of 7.8, and was addressed by a kernel patch (with module-blacklist mitigation available) though no active exploitation has been reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.