INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Fragnesia Flaw Exploit Local Root Access

| 2026-05-14 13:00 HIGH MEDIUM
Executive Summary AI-generated
A new variant in the Dirty Frag family of Linux local privilege escalation flaws has surfaced, dubbed Fragnesia and tracked as CVE-2026-46300. This third root-level kernel bug was discovered three weeks ago by William Bowling of Zellic and the V12 team. The vulnerability allows unprivileged local users to gain root access through a working proof-of-concept exploit published on May 13, which involves rewriting opening bytes in /usr/bin/su with short payloads that drop to a root shell. This flaw affects all Linux kernels released before its discovery date of May 14 and enables arbitrary writes into the kernel page cache of read-only files, potentially leading to severe security breaches.
Technical Mitigations AI-generated
• Restrict unprivileged user namespaces • Monitor for suspicious namespace creation or XFRM manipulation • Disable esp4, esp6 and rxrpc kernel modules
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-43500CVE-2026-43500 CVE-2026-43284CVE-2026-43284 CVE-2026-31431CVE-2026-31431 CVE-2026-46300CVE-2026-46300
Target & Sectors
NORTH_AMERICA NORTH_AMERICA defensedefense
Incident Timeline
‎2026/04/11
Threat actors exploited a previously unknown flaw in the Linux kernel, specifically in the same area as last month's Copy Fail bug, to gain root access on affected systems.
infrastructure Linux
organisation Copy Fail
‎April 29
Threat actors exploited a newly disclosed Linux kernel local privilege escalation flaw (CVE-2026-31431) to gain root access for local users.
tactic Privilege Escalation
infrastructure Linux
organisation CVE-2026-31431
vulnerability CVE-2026-43284
vulnerability CVE-2026-43500
organisation CVE-2026
‎April 30
Linux maintainers received private information about a newly discovered flaw in Fragnesia on April 30.
infrastructure Linux
‎May 1
Threat actors exploited a newly discovered flaw in Linux, gaining root access to affected systems.
infrastructure Linux
‎2026/05/04
Red Hat acknowledged the discovery of Dirty Frag and published an exploit describing its technical aspects on May 4, 2026.
organisation PoC
‎2026/05/06
Linux kernel versions prior to May 13, 2026, were affected by the Dirty Frag vulnerability.
infrastructure Linux
‎May 7
Threat actors used a previously unknown Linux kernel local privilege escalation flaw (CVE-2026-31431) to gain root access for local users on May 7.
tactic Privilege Escalation
infrastructure Linux
organisation CVE-2026-31431
vulnerability CVE-2026-43284
vulnerability CVE-2026-43500
organisation CVE-2026
‎May 8
Threat actors exploited a newly discovered flaw in AlmaLinux and Ubuntu operating systems to gain root access for local users.
organisation AlmaLinux
‎2026/05/11
Linux systems with the Dirty Frag flaw were exploited to gain root access by threat actors using this vulnerability.
infrastructure Linux
‎May 12
Threat actors exploited a newly discovered flaw in the Fragnesia software, gaining root access to local Linux systems.
organisation the Autonomous Validation Summit
general_metric 14 May
‎May 13
The proof-of-concept exploit was published alongside the disclosure on May 13.
organisation PoC
‎May 13, 2026
Threat actors exploited a known vulnerability in Linux, specifically the Dirty Frag flaw, which allows local users to gain root access.
infrastructure Linux
‎2026/05/14
Dirty Frag works by chaining two separate kernel flaws, the xfrm-ESP Page-Cache Write vulnerability (CVE-2026-43284) and a RxRPC Page-Cache Write security issue (CVE-2026-43500), to modify protected system files in memory without authorization.
infrastructure Linux
organisation PoC
organisation Zellic
organisation the /usr/bin/su
organisation IPsec
organisation PackageKit
organisation Microsoft Defender
organisation the RxRPC
organisation Copy Fail
organisation LPE
organisation New Fragnesia Linux
organisation Dirty Pipe
organisation Ubuntu, Red Hat Enterprise Linux
organisation AlmaLinux
organisation esp4/esp6
organisation Red Hat
organisation RAM
organisation The Linux Kernel Organization
organisation DirtyFrag
organisation Canonical Ubuntu
organisation Impacted Versions
organisation Red Hat Enterprise
organisation Important
organisation SUSE
organisation Amazon Linux
organisation CVE-2026
organisation CVSS
organisation V12
organisation TCP
organisation AES
organisation /usr/bin/su
organisation Dirty Frag
organisation Dirty Pipe's
organisation BOD
organisation Microsoft Defender Security Resarch Team
organisation GitHub
organisation Andrew File System
organisation SuseLinux
organisation SSH
organisation SELinux
organisation Security Context Constraints (SCC
organisation Hackread.com
organisation Principal Cybersecurity Engineer
organisation Black Duck
organisation National Cyber Security Centre
organisation HackerOne
organisation NCSC
‎May 15
Threat actors exploited a newly discovered flaw in Linux, gaining root access to affected systems.
infrastructure Linux
Tactical Metrics
Metrics
infrastructure
‎Linux
Affected Product
Intelligence Sources