INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Fragnesia Linux Kernel Bug Enables Local Root Access Attacks
| 2026-05-14 17:57 HIGH HIGH VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
A new Linux kernel privilege escalation vulnerability named Fragnesia, tracked as CVE-2026-46300 with a CVSS score of 7.8, was disclosed on May 14, 2026. The vulnerability allows local attackers to gain root access through page cache corruption in the XFRM ESP-in-TCP subsystem. Experts warn that this issue is dangerous because low-privileged attackers can modify read-only files in memory and take complete control of vulnerable systems. Researchers discovered the bug by William Bowling of the V12 security team, while Wiz published a detailed technical analysis. The vulnerability affects major Linux distributions without requiring race conditions or complicated timing attacks, and several vendors have released advisories and security updates, including Debian, Ubuntu, Red Hat, SUSE, Amazon Linux, AlmaLinux, and Gentoo.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-46300 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-46300CVE-2026-46300
Target & Sectors
Global Scope
Incident Timeline
2026/05/14
Threat actors can exploit the Fragnesia Linux kernel bug, tracked as CVE-2026-46300, to gain local root access via page cache corruption without requiring any race condition.
Click on any entity below to view its context and source!
infrastructure
Linux
Researchers disclosed a new Linux kernel privilege escalation vulnerability named
Fragnesia
, tracked as CVE-2026-46300 (CVSS score of 7.8).
Fragnesia shares similarities with earlier Linux privilege escalation flaws, such as
Dirty Frag
and
Copy Fail
.
Linux Kernel bug Fragnesia allows local root access attacks
Fragnesia, a new Linux kernel flaw tracked as CVE-2026-46300, could let local attackers gain root access through page cache corruption.
Codenamed
Fragnesia
, the security vulnerability is tracked as CVE-2026-46300 (CVSS score: 7.8) and is rooted in the Linux kernel's XFRM ESP-in-TCP subsystem.
Linux Kernel bug Fragnesia allows local root access attacks.
According to researchers, the bug can reliably provide root access on major Linux distributions without requiring race conditions or complicated timing attacks.
“Fragnesia exploits a logic flaw in the Linux XFRM ESP-in-TCP implementation, specifically involving improper handling of shared page fragments during skb coalescing.” states the report.
Several Linux vendors have already released advisories and security updates, including Debian, Ubuntu, Red Hat, SUSE, Amazon Linux, AlmaLinux, and Gentoo.
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Linux Fragnesia)
Ravie Lakshmanan
May 14, 2026
Vulnerability / Linux
Details have emerged about a new variant of the recent
Dirty Frag
Linux local privilege escalation (LPE) vulnerability that allows local attackers to gain root access, making it the thir…
New Fragnesia Linux Kernel LPE Grants Root Access via Page Cache Corruption.
Advisories have been released by multiple Linux distributions -
"This is a separate bug in the ESP/XFRM from Dirty Frag which has received its own patch," V12 said.
It abuses a logic bug in the Linux XFRM ESP-in-TCP subsystem to achieve arbitrary byte writes into the kernel page cache of read-only files, without requiring any race condition.
The development comes as a threat actor named "berz0k" has been observed advertising on cybercrime forums a zero-day Linux LPE exploit for $170,000, claiming it works on multiple major Linux distributions.
Tactical Metrics
Metrics
infrastructure
Linux
Affected Product
Click for context!
Researchers disclosed a new Linux kernel privilege escalation vulnerability named
Fragnesia
, tracked as CVE-2026-46300 (CVSS score of 7.8).
Fragnesia shares similarities with earlier Linux privilege escalation flaws, such as
Dirty Frag
and
Copy Fail
.
Linux Kernel bug Fragnesia allows local root access attacks.
Linux Kernel bug Fragnesia allows local root access attacks
Fragnesia, a new Linux kernel flaw tracked as CVE-2026-46300, could let local attackers gain root access through page cache corruption.
According to researchers, the bug can reliably provide root access on major Linux distributions without requiring race conditions or complicated timing attacks.
“Fragnesia exploits a logic flaw in the Linux XFRM ESP-in-TCP implementation, specifically involving improper handling of shared page fragments during skb coalescing.” states the report.
Several Linux vendors have already released advisories and security updates, including Debian, Ubuntu, Red Hat, SUSE, Amazon Linux, AlmaLinux, and Gentoo.
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Linux Fragnesia)
Ravie Lakshmanan
May 14, 2026
Vulnerability / Linux
Details have emerged about a new variant of the recent
Dirty Frag
Linux local privilege escalation (LPE) vulnerability that allows local attackers to gain root access, making it the thir…
New Fragnesia Linux Kernel LPE Grants Root Access via Page Cache Corruption.
Codenamed
Fragnesia
, the security vulnerability is tracked as CVE-2026-46300 (CVSS score: 7.8) and is rooted in the Linux kernel's XFRM ESP-in-TCP subsystem.
Advisories have been released by multiple Linux distributions -
"This is a separate bug in the ESP/XFRM from Dirty Frag which has received its own patch," V12 said.
It abuses a logic bug in the Linux XFRM ESP-in-TCP subsystem to achieve arbitrary byte writes into the kernel page cache of read-only files, without requiring any race condition.
The development comes as a threat actor named "berz0k" has been observed advertising on cybercrime forums a zero-day Linux LPE exploit for $170,000, claiming it works on multiple major Linux distributions.
Intelligence Sources
The Hacker News
2026-05-14
Security Affairs
2026-05-14
Linux Kernel bug Fragnesia allows local root access attacks
Security Affairs
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T11:05
Comprehensive Tactical Telemetry
Highly Correlated Entities
23x
organisation
Identified Entity
CVE-2026-46300
entity
Contextual Telemetry
Context Block
7 METRICS
tactic
Cyber Operation Type
Privilege Escalation
tactic
vulnerability
Exploited CVE
CVE-2026-46300
cve
vulnerability
CVSS Score
8
score
infrastructure
Affected Product
Linux
software
general metric
Cve-2026
46,300
cve-2026
timeline
Temporal Reference
May 14, 2026
date
general metric
Codenamed Fragnesia
8
codenamed fragnesia
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.