INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Fragnesia Linux Kernel Bug Enables Local Root Access Attacks

| 2026-05-14 17:57 HIGH HIGH VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
A new Linux kernel privilege escalation vulnerability named Fragnesia, tracked as CVE-2026-46300 with a CVSS score of 7.8, was disclosed on May 14, 2026. The vulnerability allows local attackers to gain root access through page cache corruption in the XFRM ESP-in-TCP subsystem. Experts warn that this issue is dangerous because low-privileged attackers can modify read-only files in memory and take complete control of vulnerable systems. Researchers discovered the bug by William Bowling of the V12 security team, while Wiz published a detailed technical analysis. The vulnerability affects major Linux distributions without requiring race conditions or complicated timing attacks, and several vendors have released advisories and security updates, including Debian, Ubuntu, Red Hat, SUSE, Amazon Linux, AlmaLinux, and Gentoo.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-46300 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-46300CVE-2026-46300
Target & Sectors
Global Scope
Incident Timeline
‎2026/05/14
Threat actors can exploit the Fragnesia Linux kernel bug, tracked as CVE-2026-46300, to gain local root access via page cache corruption without requiring any race condition.
infrastructure Linux
Tactical Metrics
Metrics
infrastructure
‎Linux
Affected Product
Intelligence Sources