logo

Fragnesia Linux Kernel Flaw Enables Root Privilege Escalation

ID: b7368c14-ab29-5c91-9ecc-bdf8dffe3dea

STIX ID: report--b7368c14-ab29-5c91-9ecc-bdf8dffe3dea

Feed Name: The Cyber Express

Threat Score
70/100

Date Published: 2026-05-15

Date Updated: 2026-07-20

Author: Ashish Khaitan

...
...

Security researchers disclosed "Fragnesia" (CVE-2026-46300), a local Linux kernel privilege escalation that exploits a logic flaw in the XFRM ESP-in-TCP implementation to perform deterministic page-cache corruption and obtain root from an unprivileged namespace; a public proof-of-concept exists but there is no confirmed evidence of active in-the-wild exploitation. Patches are being rolled out across distributions, and recommended mitigations include applying vendor kernel updates, disabling vulnerable modules (esp4, esp6, rxrpc), restricting unprivileged user namespaces, and monitoring for suspicious XFRM or AF_ALG activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.