Fragnesia (CVE-2026-46300): Frequently asked questions about new Linux Kernel XFRM ESP-in-TCP privilege escalation
CVE-2026-46300, known as Fragnesia, is a Linux kernel vulnerability that enables an unprivileged local attacker to escalate privileges to root on the host. It specifically affects GKE Standard clusters running Ubuntu nodes, while GKE Standard clusters with Container-Optimized OS nodes, GKE Autopilot, and GKE Sandbox are not impacted. Upstream kernel patches have recently been released but are still being integrated into GKE releases. Partial mitigations include running workloads as non-root, using seccomp profiles set to RuntimeDefault, and disabling privilege escalation in container security contexts. Patch versions for other affected environments like VMware GDC and GKE on AWS/Azure are pending. The vulnerability is rated as high severity due to the potential for container breakout and host compromise.
AI Analysis
Technical Summary
CVE-2026-46300 (Fragnesia) is a privilege escalation vulnerability in the Linux kernel's XFRM ESP-in-TCP implementation. It allows an unprivileged local attacker within a container to escalate privileges to root on the host system, effectively enabling container breakout. The vulnerability impacts Google Kubernetes Engine (GKE) Standard clusters with Ubuntu nodes. Other GKE environments such as those using Container-Optimized OS nodes, Autopilot, or Sandbox are not affected. Upstream kernel patches addressing this issue have been released recently and are being incorporated into GKE releases. Interim mitigations include running workloads as non-root, applying seccomp profiles with RuntimeDefault, and setting allowPrivilegeEscalation to false in pod security contexts. Patch details and severity assessments for VMware GDC, GKE on AWS, GKE on Azure, and bare metal GDC are forthcoming.
Potential Impact
This vulnerability allows an unprivileged local attacker inside a container to escalate privileges to root on the host, leading to a container breakout. This compromises the host system's security and undermines container isolation. The impact is significant in environments using GKE Standard clusters with Ubuntu nodes. Other GKE environments and configurations are not impacted. The vulnerability poses a high risk due to the potential for full host compromise from a container context.
Mitigation Recommendations
Upstream kernel patches have been released and are being integrated into GKE releases; monitor vendor advisories for patch availability. In the meantime, use GKE Sandbox for secure workload isolation where possible. Migrate workloads to run as non-root users. For containers requiring root, set pod.spec.securityContext.seccompProfile.type to RuntimeDefault and pod.spec.containers[*].securityContext.allowPrivilegeEscalation to false. These mitigations reduce the risk of privilege escalation until patches are fully deployed. Patch versions and guidance for VMware GDC, GKE on AWS, GKE on Azure, and bare metal GDC are pending; follow updates from respective vendors.
Fragnesia (CVE-2026-46300): Frequently asked questions about new Linux Kernel XFRM ESP-in-TCP privilege escalation
Description
CVE-2026-46300, known as Fragnesia, is a Linux kernel vulnerability that enables an unprivileged local attacker to escalate privileges to root on the host. It specifically affects GKE Standard clusters running Ubuntu nodes, while GKE Standard clusters with Container-Optimized OS nodes, GKE Autopilot, and GKE Sandbox are not impacted. Upstream kernel patches have recently been released but are still being integrated into GKE releases. Partial mitigations include running workloads as non-root, using seccomp profiles set to RuntimeDefault, and disabling privilege escalation in container security contexts. Patch versions for other affected environments like VMware GDC and GKE on AWS/Azure are pending. The vulnerability is rated as high severity due to the potential for container breakout and host compromise.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-46300 (Fragnesia) is a privilege escalation vulnerability in the Linux kernel's XFRM ESP-in-TCP implementation. It allows an unprivileged local attacker within a container to escalate privileges to root on the host system, effectively enabling container breakout. The vulnerability impacts Google Kubernetes Engine (GKE) Standard clusters with Ubuntu nodes. Other GKE environments such as those using Container-Optimized OS nodes, Autopilot, or Sandbox are not affected. Upstream kernel patches addressing this issue have been released recently and are being incorporated into GKE releases. Interim mitigations include running workloads as non-root, applying seccomp profiles with RuntimeDefault, and setting allowPrivilegeEscalation to false in pod security contexts. Patch details and severity assessments for VMware GDC, GKE on AWS, GKE on Azure, and bare metal GDC are forthcoming.
Potential Impact
This vulnerability allows an unprivileged local attacker inside a container to escalate privileges to root on the host, leading to a container breakout. This compromises the host system's security and undermines container isolation. The impact is significant in environments using GKE Standard clusters with Ubuntu nodes. Other GKE environments and configurations are not impacted. The vulnerability poses a high risk due to the potential for full host compromise from a container context.
Mitigation Recommendations
Upstream kernel patches have been released and are being integrated into GKE releases; monitor vendor advisories for patch availability. In the meantime, use GKE Sandbox for secure workload isolation where possible. Migrate workloads to run as non-root users. For containers requiring root, set pod.spec.securityContext.seccompProfile.type to RuntimeDefault and pod.spec.containers[*].securityContext.allowPrivilegeEscalation to false. These mitigations reduce the risk of privilege escalation until patches are fully deployed. Patch versions and guidance for VMware GDC, GKE on AWS, GKE on Azure, and bare metal GDC are pending; follow updates from respective vendors.
Technical Details
- Article Source
- {"url":"https://www.tenable.com/blog/fragnesia-cve-2026-46300-faq-about-new-linux-kernel-xfrm-esp-in-tcp-priv-esc","fetched":true,"fetchedAt":"2026-05-26T20:29:13.025Z","wordCount":2690}
- Classification
- {"confidence":0.91,"severitySource":"stated","classifier":"rss-v2"}
Threat ID: 6a160299e29bf47b505d4a82
Added to database: 05/26/2026, 20:29:13 UTC
Last enriched: 08/04/2026, 13:03:21 UTC
Last updated: 09/12/2026, 22:01:34 UTC
Views: 160
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.