Fragnesia LPE Uses Kernel Page Cache to Grant Root Access (CVE-2026-46300)

1 min read
Source: The Hacker News
Fragnesia LPE Uses Kernel Page Cache to Grant Root Access (CVE-2026-46300)
Photo: The Hacker News
TL;DR Summary

A new Linux kernel local privilege escalation called Fragnesia (CVE-2026-46300) targets the XFRM ESP-in-TCP subsystem to corrupt the kernel page cache and convert unprivileged users into root. A PoC has been released, advisories have been issued by major distros, and patches are available. Users should patch promptly or apply Dirty Frag mitigations (e.g., disable esp4/esp6 and harden containers) while monitoring for escalation attempts. A threat actor, berz0k, is advertising a zero-day LPE exploit for sale on cybercrime forums.

Share this article

Reading Insights

Total Reads

0

Unique Readers

10

Time Saved

2 min

vs 3 min read

Condensed

84%

47578 words

Want the full story? Read the original article

Read on The Hacker News