Fragnesia Linux Kernel Flaw Enables Root Privilege Escalation
ID: b7368c14-ab29-5c91-9ecc-bdf8dffe3dea
STIX ID: report--b7368c14-ab29-5c91-9ecc-bdf8dffe3dea
Feed Name: The Cyber Express
Security researchers disclosed "Fragnesia" (CVE-2026-46300), a local Linux kernel privilege escalation that exploits a logic flaw in the XFRM ESP-in-TCP implementation to perform deterministic page-cache corruption and obtain root from an unprivileged namespace; a public proof-of-concept exists but there is no confirmed evidence of active in-the-wild exploitation. Patches are being rolled out across distributions, and recommended mitigations include applying vendor kernel updates, disabling vulnerable modules (esp4, esp6, rxrpc), restricting unprivileged user namespaces, and monitoring for suspicious XFRM or AF_ALG activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
