logo

Fragnesia: Linux Kernel Local Privilege Escalation via ESP-in-TCP

ID: 0833bfba-71d3-524a-b36f-f575c77240c7

STIX ID: report--0833bfba-71d3-524a-b36f-f575c77240c7

Feed Name: Wiz Blog

Threat Score
75/100

Date Published: 2026-05-13

Date Updated: 2026-05-13

Author: Merav Bar

...
...

Wiz Research disclosed “Fragnesia,” a new DirtyFrag-related Linux local privilege escalation that exploits a logic flaw in the XFRM ESP-in-TCP implementation to deterministically corrupt page-cache contents via in-place AES-GCM decryption, allowing unprivileged attackers (using user/network namespaces and NETLINK_XFRM) to achieve root by modifying in-memory binaries; mitigations include applying vendor kernel patches, disabling the affected modules (esp4/esp6/rxrpc), restricting unprivileged user namespaces, and rebooting or clearing page cache if exploitation is suspected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.