Linux Kernel bug Fragnesia allows local root access attacks
Overview
Researchers have identified a new vulnerability in the Linux kernel, named Fragnesia and tracked as CVE-2026-46300, which could allow local attackers to gain root access through page cache corruption. This flaw affects the XFRM ESP-in-TCP subsystem and has a CVSS score of 7.8, indicating a significant risk. If exploited, it could enable attackers to take complete control of the affected systems. It's crucial for users of affected Linux systems to be aware of this vulnerability and take necessary precautions. The disclosure of this flaw highlights ongoing security challenges within the Linux ecosystem.
Key Takeaways
- Affected Systems: Linux kernel, specifically the XFRM ESP-in-TCP subsystem.
- Action Required: Users should apply any available updates or patches to the Linux kernel as they are released by their distributions.
- Timeline: Newly disclosed
Original Article Summary
Fragnesia, a new Linux kernel flaw tracked as CVE-2026-46300, could let local attackers gain root access through page cache corruption. Researchers disclosed a new Linux kernel privilege escalation vulnerability named Fragnesia, tracked as CVE-2026-46300 (CVSS score of 7.8). The flaw affects the XFRM ESP-in-TCP subsystem and could allow local attackers to gain full root access […]
Impact
Linux kernel, specifically the XFRM ESP-in-TCP subsystem.
Exploitation Status
No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.
Timeline
Newly disclosed
Remediation
Users should apply any available updates or patches to the Linux kernel as they are released by their distributions. It's advisable to monitor security bulletins from vendors for specific mitigation strategies related to CVE-2026-46300.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Linux, CVE, Vulnerability, and 1 more.