logo

Fragnesia Extends Linux Kernel Security Challenge with Root-Level Exploit

ID: 4d41e221-0e02-5003-a39c-c7fe8d6738a1

STIX ID: report--4d41e221-0e02-5003-a39c-c7fe8d6738a1

Feed Name: Security Boulevard

Threat Score
78/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: James Maguire

...
...

A newly disclosed Linux kernel privilege-escalation vulnerability (CVE-2026-46300, "Fragnesia") in the XFRM ESP-in-TCP subsystem allows unprivileged users to corrupt file-backed page cache entries in memory and obtain root access without modifying disk files. The flaw—reported as predictable and avoiding race conditions—affects multiple major distributions; vendors have issued advisories and recommended temporary mitigations (disabling esp4/esp6/rxrpc, restricting unprivileged namespaces). Public exploit demonstrations exist, but researchers have not observed confirmed in-the-wild exploitation to date.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.