Fragnesia (CVE-2026-46300): Frequently asked questions about new Linux Kernel XFRM ESP-in-TCP privilege escalation
CVE-2026-46300, known as Fragnesia, is a high severity local privilege escalation vulnerability in the Linux kernel's XFRM ESP-in-TCP subsystem. It allows any local user to gain root privileges by exploiting improper handling of socket buffer fragments, specifically due to a failure to propagate a shared page flag that leads to unsafe write operations. A public proof-of-concept exploit exists and has been confirmed on Ubuntu systems. The vulnerability affects Linux kernels that have not applied the May 13 patch. Module blacklisting used for a related vulnerability (Dirty Frag) also protects against Fragnesia, but systems patched only for Dirty Frag remain vulnerable. Immediate kernel updates or module blacklisting are recommended. No in-the-wild exploitation has been reported so far.
AI Analysis
Technical Summary
Fragnesia (CVE-2026-46300) is a local privilege escalation vulnerability in the Linux kernel's XFRM ESP-in-TCP subsystem. The flaw arises from improper handling of socket buffer fragments, specifically a failure to propagate a shared page flag, which results in unsafe write operations that can be exploited by any local user to gain root privileges. A public proof-of-concept exploit has been demonstrated on Ubuntu systems. The vulnerability affects Linux kernels that have not applied the patch released on May 13, 2026. While module blacklisting used to mitigate the related Dirty Frag vulnerability also protects against Fragnesia, systems patched only for Dirty Frag remain vulnerable. Immediate remediation involves applying the official kernel patch or blacklisting the vulnerable module. No confirmed exploitation in the wild has been reported to date.
Potential Impact
Successful exploitation of this vulnerability allows any local user to escalate privileges to root on affected Linux systems. This can lead to full system compromise, unauthorized access to sensitive data, and the ability to execute arbitrary code with kernel-level privileges. However, there are no reports of active exploitation in the wild at this time.
Mitigation Recommendations
A patch addressing this vulnerability was released on May 13, 2026. Applying this official kernel update is the primary recommended mitigation. Alternatively, blacklisting the vulnerable kernel module provides protection but is less comprehensive. Systems patched only for the related Dirty Frag vulnerability remain vulnerable to Fragnesia, so ensure the specific Fragnesia patch or module blacklisting is applied. Monitor vendor advisories for updates and confirm patch application. No additional action is required if the May 13 patch has been applied.
Fragnesia (CVE-2026-46300): Frequently asked questions about new Linux Kernel XFRM ESP-in-TCP privilege escalation
Description
CVE-2026-46300, known as Fragnesia, is a high severity local privilege escalation vulnerability in the Linux kernel's XFRM ESP-in-TCP subsystem. It allows any local user to gain root privileges by exploiting improper handling of socket buffer fragments, specifically due to a failure to propagate a shared page flag that leads to unsafe write operations. A public proof-of-concept exploit exists and has been confirmed on Ubuntu systems. The vulnerability affects Linux kernels that have not applied the May 13 patch. Module blacklisting used for a related vulnerability (Dirty Frag) also protects against Fragnesia, but systems patched only for Dirty Frag remain vulnerable. Immediate kernel updates or module blacklisting are recommended. No in-the-wild exploitation has been reported so far.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Fragnesia (CVE-2026-46300) is a local privilege escalation vulnerability in the Linux kernel's XFRM ESP-in-TCP subsystem. The flaw arises from improper handling of socket buffer fragments, specifically a failure to propagate a shared page flag, which results in unsafe write operations that can be exploited by any local user to gain root privileges. A public proof-of-concept exploit has been demonstrated on Ubuntu systems. The vulnerability affects Linux kernels that have not applied the patch released on May 13, 2026. While module blacklisting used to mitigate the related Dirty Frag vulnerability also protects against Fragnesia, systems patched only for Dirty Frag remain vulnerable. Immediate remediation involves applying the official kernel patch or blacklisting the vulnerable module. No confirmed exploitation in the wild has been reported to date.
Potential Impact
Successful exploitation of this vulnerability allows any local user to escalate privileges to root on affected Linux systems. This can lead to full system compromise, unauthorized access to sensitive data, and the ability to execute arbitrary code with kernel-level privileges. However, there are no reports of active exploitation in the wild at this time.
Mitigation Recommendations
A patch addressing this vulnerability was released on May 13, 2026. Applying this official kernel update is the primary recommended mitigation. Alternatively, blacklisting the vulnerable kernel module provides protection but is less comprehensive. Systems patched only for the related Dirty Frag vulnerability remain vulnerable to Fragnesia, so ensure the specific Fragnesia patch or module blacklisting is applied. Monitor vendor advisories for updates and confirm patch application. No additional action is required if the May 13 patch has been applied.
Technical Details
- Article Source
- {"url":"https://www.tenable.com/blog/fragnesia-cve-2026-46300-faq-about-new-linux-kernel-xfrm-esp-in-tcp-priv-esc","fetched":true,"fetchedAt":"2026-05-26T20:29:13.025Z","wordCount":2690}
Threat ID: 6a160299e29bf47b505d4a82
Added to database: 05/26/2026, 20:29:13 UTC
Last enriched: 06/10/2026, 16:52:20 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 120
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.