BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Linux Fragnesia CVE-2026-46300 LPE Vulnerability Uncovered

New Linux kernel Fragnesia flaw grants root access, similar to recent critical bugs.

  • A new Linux kernel vulnerability dubbed “Fragnesia” (CVE-2026-46300) allows unprivileged local attackers to gain root access.
  • The bug is in the XFRM ESP-in-TCP subsystem and provides a deterministic page-cache corruption primitive, similar to recent Dirty Frag and Copy Fail exploits.
  • A proof-of-concept exploit has been released, and patches/mitigations are available, though no in-the-wild exploitation has been observed yet.

A third critical Linux kernel vulnerability has surfaced, allowing attackers to gain root access on systems, as detailed by researcher William Bowling in May 2026. The flaw, codenamed Fragnesia and tracked as CVE-2026-46300, exploits the kernel’s XFRM ESP-in-TCP subsystem, providing a deterministic corruption primitive without requiring a race condition. Consequently, this marks another significant escalation risk for Linux distributions within a volatile two-week period.

- Advertisement -

According to security advisories and reports from Google-owned Wiz, the vulnerability lets local attackers modify read-only file contents in the kernel page cache to achieve privilege escalation. Fragnesia is similar to the recently disclosed Copy Fail and Dirty Frag bugs, immediately yielding root on major distributions by corrupting the page cache memory of the /usr/bin/su binary. Meanwhile, a threat actor named “berz0k” has been observed advertising a zero-day Linux LPE exploit for $170,000 on cybercrime forums.

Red Hat stated it is performing an assessment to confirm if existing mitigations extend to this new flaw, while CloudLinux maintainers noted customers with the Dirty Frag mitigation need no further action until patched kernels are released. However, Microsoft urged users to apply patches promptly and consider the same mitigations used for Dirty Frag if patching isn’t immediately possible. These mitigations include disabling esp4, esp6, and related xfrm/IPsec functionality, as well as restricting unnecessary local shell access.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Apple’s Vision Pro VP Joins OpenAI’s Hardware Push

Paul Meade, the VP of hardware engineering for Apple's Vision Pro and smart glasses,...

Kenyan startup Tando lets M-Pesa users send bitcoin via Lightning

Kenyan startup Tando enables 40 million M-Pesa users to send and receive Bitcoin without...

FBI: Russia Phishes Signal Keys to Hijack Accounts

Russian intelligence actors are using sophisticated phishing to steal Signal Backup Recovery Keys, allowing...

Strategy’s STRC Hits Record Low, Now 29% Below Par Value

Strategy's STRC share price has plunged to a new all-time low of $71.25, nearly...

Linux ‘Pedit COW’ Flaw Lets Local Users Gain Root

A new Linux kernel vulnerability, CVE-2026-46331, allows local, unprivileged users to gain full root...

Must Read

What Is Binance Earn?

As someone who is passionate about cryptocurrency, I am always on the lookout for new opportunities to grow my portfolio. That's why I was...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading