BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Linux Fragnesia CVE-2026-46300 LPE Vulnerability Uncovered

New Linux kernel Fragnesia flaw grants root access, similar to recent critical bugs.

  • A new Linux kernel vulnerability dubbed “Fragnesia” (CVE-2026-46300) allows unprivileged local attackers to gain root access.
  • The bug is in the XFRM ESP-in-TCP subsystem and provides a deterministic page-cache corruption primitive, similar to recent Dirty Frag and Copy Fail exploits.
  • A proof-of-concept exploit has been released, and patches/mitigations are available, though no in-the-wild exploitation has been observed yet.

A third critical Linux kernel vulnerability has surfaced, allowing attackers to gain root access on systems, as detailed by researcher William Bowling in May 2026. The flaw, codenamed Fragnesia and tracked as CVE-2026-46300, exploits the kernel’s XFRM ESP-in-TCP subsystem, providing a deterministic corruption primitive without requiring a race condition. Consequently, this marks another significant escalation risk for Linux distributions within a volatile two-week period.

- Advertisement -

According to security advisories and reports from Google-owned Wiz, the vulnerability lets local attackers modify read-only file contents in the kernel page cache to achieve privilege escalation. Fragnesia is similar to the recently disclosed Copy Fail and Dirty Frag bugs, immediately yielding root on major distributions by corrupting the page cache memory of the /usr/bin/su binary. Meanwhile, a threat actor named “berz0k” has been observed advertising a zero-day Linux LPE exploit for $170,000 on cybercrime forums.

Red Hat stated it is performing an assessment to confirm if existing mitigations extend to this new flaw, while CloudLinux maintainers noted customers with the Dirty Frag mitigation need no further action until patched kernels are released. However, Microsoft urged users to apply patches promptly and consider the same mitigations used for Dirty Frag if patching isn’t immediately possible. These mitigations include disabling esp4, esp6, and related xfrm/IPsec functionality, as well as restricting unnecessary local shell access.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

IMF: Tokenization reshapes markets, but risks remain

The IMF warns tokenization could reshape markets but faces legal uncertainty and stability risks.Tokenized...

Justin Sun Prize winners announced but prize details unclear

Justin Sun has spent the past week announcing winners of the Justin Sun Prize,...

OpenAI publishes 722 math papers; only 162 are Lean-verified

OpenAI published 722 math manuscripts on GitHub on Tuesday, all produced by an internal...

Musk claims Indian oligarchs block Starlink launch in India

Elon Musk accused unnamed Indian oligarchs of blocking Starlink's launch to protect a "monopolistic...

SecondFi offers $7.60 per NFT in $21M hack recovery

SecondFi launched a recovery portal for victims of its $21 million Cardano wallet hack,...

Must Read

Top 10 BEST Crypto Trading Books for New Traders

If you're thinking of diving into the crypto trading space, acquiring solid knowledge isn't just recommended - it's essential to protect your investment.Learning...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading