A new high-severity local privilege escalation vulnerability in the Linux kernel, dubbed “Fragnesia” and tracked as CVE-2026-46300 (CVSS 7.8), has been publicly disclosed along with a working proof-of-concept exploit. Discovered by William Bowling of Zellic and the V12 security team, the flaw affects the kernel’s XFRM ESP-in-TCP subsystem.

Fragnesia allows unprivileged local attackers to modify the contents of read-only files within the kernel’s page cache through a deterministic page-cache corruption primitive. The exploit works by triggering in-place AES-GCM decryption directly over page-cache pages via a logic bug in the ESP-in-TCP receive path. An attacker can XOR a chosen keystream into read-only files — such as /usr/bin/su — to gain root privileges. Critically, this exploit does not rely on a race condition, making it highly reliable.

Fragnesia is part of the broader “Dirty Frag” family of page-cache corruption vulnerabilities, joining “Copy Fail” and the infamous “Dirty Pipe.” Major distributions including Ubuntu, Red Hat, SUSE, and AlmaLinux are affected and actively releasing patches. Systems without the espintcp module (such as Amazon Linux and Bottlerocket) are not impacted.

Source

The Hacker News — New Fragnesia Linux Kernel LPE Grants Root | LinuxSecurity.com

Commentary

The “Dirty” family of Linux kernel vulnerabilities keeps growing, and Fragnesia is arguably the most concerning entry yet. Unlike race-condition-dependent exploits that are finicky and unreliable in practice, Fragnesia’s deterministic corruption primitive means the exploit works consistently — which is exactly what you don’t want when a PoC is already public.

The saving grace is that it’s a local privilege escalation, not remote — an attacker needs existing code execution on the system first. But in multi-tenant environments, containers with shared kernels, or any scenario where unprivileged users exist alongside sensitive workloads, this is a critical patch-now situation. Check if your kernel loads espintcp and patch accordingly.

By Allan