BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Linux Fragnesia CVE-2026-46300 LPE Vulnerability Uncovered

New Linux kernel Fragnesia flaw grants root access, similar to recent critical bugs.

  • A new Linux kernel vulnerability dubbed “Fragnesia” (CVE-2026-46300) allows unprivileged local attackers to gain root access.
  • The bug is in the XFRM ESP-in-TCP subsystem and provides a deterministic page-cache corruption primitive, similar to recent Dirty Frag and Copy Fail exploits.
  • A proof-of-concept exploit has been released, and patches/mitigations are available, though no in-the-wild exploitation has been observed yet.

A third critical Linux kernel vulnerability has surfaced, allowing attackers to gain root access on systems, as detailed by researcher William Bowling in May 2026. The flaw, codenamed Fragnesia and tracked as CVE-2026-46300, exploits the kernel’s XFRM ESP-in-TCP subsystem, providing a deterministic corruption primitive without requiring a race condition. Consequently, this marks another significant escalation risk for Linux distributions within a volatile two-week period.

- Advertisement -

According to security advisories and reports from Google-owned Wiz, the vulnerability lets local attackers modify read-only file contents in the kernel page cache to achieve privilege escalation. Fragnesia is similar to the recently disclosed Copy Fail and Dirty Frag bugs, immediately yielding root on major distributions by corrupting the page cache memory of the /usr/bin/su binary. Meanwhile, a threat actor named “berz0k” has been observed advertising a zero-day Linux LPE exploit for $170,000 on cybercrime forums.

Red Hat stated it is performing an assessment to confirm if existing mitigations extend to this new flaw, while CloudLinux maintainers noted customers with the Dirty Frag mitigation need no further action until patched kernels are released. However, Microsoft urged users to apply patches promptly and consider the same mitigations used for Dirty Frag if patching isn’t immediately possible. These mitigations include disabling esp4, esp6, and related xfrm/IPsec functionality, as well as restricting unnecessary local shell access.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

XRP Rallies 3.25% on Trump Clarity Act Ethics Deal

XRP jumped 3.25% to $1.1485, ranking third among top-50 performers, behind Ondo and Cardano.Reports...

Bitcoin Tops $66K After BlackRock CEO’s Bullish Forecast

Bitcoin surged past $66,000, its highest level in over a month, following a bullish...

CoinShares Launches First UCITS Bitcoin Mining ETF in Europe

CoinShares launched its first UCITS Bitcoin mining ETF in Europe, trading on Deutsche Börse...

AMD stock jumps on expanded Microsoft Azure partnership

AMD stock surged 1.58% on July 20, gaining an additional 3.56% in pre-market trading...

Moreno: DOJ, not states, to enforce CLARITY Act ethics

The White House reportedly agreed to ethics language for the CLARITY Act, potentially clearing...

Must Read

How to Buy VPN With Bitcoin Using CyberGhost VPN

In this step-by-step guide, you will learn how to purchase a VPN (Virtual Private Network) subscription using Bitcoin, a popular cryptocurrency, and CyberGhost VPN,...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading