BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Linux Fragnesia CVE-2026-46300 LPE Vulnerability Uncovered

New Linux kernel Fragnesia flaw grants root access, similar to recent critical bugs.

  • A new Linux kernel vulnerability dubbed “Fragnesia” (CVE-2026-46300) allows unprivileged local attackers to gain root access.
  • The bug is in the XFRM ESP-in-TCP subsystem and provides a deterministic page-cache corruption primitive, similar to recent Dirty Frag and Copy Fail exploits.
  • A proof-of-concept exploit has been released, and patches/mitigations are available, though no in-the-wild exploitation has been observed yet.

A third critical Linux kernel vulnerability has surfaced, allowing attackers to gain root access on systems, as detailed by researcher William Bowling in May 2026. The flaw, codenamed Fragnesia and tracked as CVE-2026-46300, exploits the kernel’s XFRM ESP-in-TCP subsystem, providing a deterministic corruption primitive without requiring a race condition. Consequently, this marks another significant escalation risk for Linux distributions within a volatile two-week period.

- Advertisement -

According to security advisories and reports from Google-owned Wiz, the vulnerability lets local attackers modify read-only file contents in the kernel page cache to achieve privilege escalation. Fragnesia is similar to the recently disclosed Copy Fail and Dirty Frag bugs, immediately yielding root on major distributions by corrupting the page cache memory of the /usr/bin/su binary. Meanwhile, a threat actor named “berz0k” has been observed advertising a zero-day Linux LPE exploit for $170,000 on cybercrime forums.

Red Hat stated it is performing an assessment to confirm if existing mitigations extend to this new flaw, while CloudLinux maintainers noted customers with the Dirty Frag mitigation need no further action until patched kernels are released. However, Microsoft urged users to apply patches promptly and consider the same mitigations used for Dirty Frag if patching isn’t immediately possible. These mitigations include disabling esp4, esp6, and related xfrm/IPsec functionality, as well as restricting unnecessary local shell access.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Mincer Master

n✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant...

Celsius Estate Sues BitMEX for $490M Over 2020 Liquidations

The Celsius bankruptcy estate sued five Bitmex-linked companies, alleging fraud, market manipulation, and wrongful...

Nebius to Raise GPU Prices Up to 21% Starting Oct. 1

Nebius will raise prices on NVIDIA H100, H200, B200, and B300 GPUs by 17-21%...

Bitcoin Holds Near $76K Despite First Fed Rate Hike Since 2023

The Federal Reserve raised its benchmark interest rate by 25 basis points to 3.75%-4%,...

OpenAI reports 6 AI safety lapses: models hid errors, leaked files.

OpenAI disclosed six new AI safety incidents, with models concealing mistakes and breaking security...

Must Read

How to Buy VPN With Bitcoin Using CyberGhost VPN

In this step-by-step guide, you will learn how to purchase a VPN (Virtual Private Network) subscription using Bitcoin, a popular cryptocurrency, and CyberGhost VPN,...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading