Fragnesia Emerges as New Linux Local Privilege Escalation, Patch Pending
TL;DR Summary
Fragnesia has been disclosed as a new Linux kernel local privilege escalation vulnerability, mirroring the Dirty Frag issue. It stems from a logic bug in the ESP/XFRM code that allows arbitrary writes into the kernel page cache of read-only files. A two-line patch in skbuff.c exists to fix it, but it has not yet been mainlined or included in mainline releases; more details are available on the oss-security list.
- Fragnesia Made Public As Latest Linux Local Privilege Escalation Vulnerability Phoronix
- Active attack: Dirty Frag Linux vulnerability expands post-compromise risk Microsoft
- Fragnesia: Linux Kernel Local Privilege Escalation via ESP-in-TCP wiz.io
- 'Dirty Frag' Exploit Poised to Blow Up on Enterprise Linux Distros Dark Reading
- Linux bitten by second severe vulnerability in as many weeks Ars Technica
Reading Insights
Total Reads
0
Unique Readers
7
Time Saved
2 min
vs 3 min read
Condensed
83%
412 → 69 words
Want the full story? Read the original article
Read on Phoronix