HomeSecurityFragnesia: New Linux kernel vulnerability provides root access

Fragnesia: New Linux kernel vulnerability provides root access

A new variant of the Dirty Frag vulnerability has raised serious security concerns for the Linux kernel , allowing local attackers to gain root privileges without any special requirements. The vulnerability, which is tracked as Fragnesia (CVE-2026-46300) and has a CVSS score of 7.8, is the third related local privilege escalation case to be discovered in the Linux kernel in just two weeks.

 Linux kernel Fragnesia

Fragnesia: Origin of the vulnerability and technical characteristics

The vulnerability is located in the XFRM ESP-in-TCP subsystem of the Linux kernel and is attributed to a logic bug that allows writes to memory areas that should normally be read-only. According to the Wiz, which is part of Google, the exploit leads to corruption of the kernel page cache, allowing unprivileged users to modify critical data and gain full system privileges. The discovery of the vulnerability is attributed to researcher William Bowling of the V12 team, who confirmed that the issue does not require a race condition, which increases the reliability of the exploit.

See also: Dirty Frag vulnerability in Linux provides root access

Widespread impact on Linux distributions and patches available

The severity of the issue is also reflected in the fact that warnings have been issued by almost all major Linux distributions, including AlmaLinux, Amazon Linux, CloudLinux, Debian, Gentoo, Red Hat Enterprise Linux, SUSE , and Ubuntu. The maintainers of V12 have stated that this is a separate bug from Dirty Frag, but it shares the same attack surface and is treated in similar ways. A proof-of-concept exploit has already been published, which increases the pressure to implement updates immediately.

Relationship to previous Dirty Frag and Copy Fail attacks

Fragnesia is part of a family of vulnerabilities such as Copy Fail and Dirty Frag, which rely on incorrect kernel memory handling. Like its predecessors, this exploit can lead to immediate root privileges by manipulating the memory of the /usr/bin/su file. The result is a global impact on systems across multiple distributions, making the vulnerability particularly dangerous for servers and containerized environments.

Fragnesia: New Linux kernel vulnerability provides root access

Protection measures and proposed mitigations

Security experts say organizations that have already applied patches for Dirty Frag are in a better position, although confirmation is needed that existing mitigations fully cover the new CVE. Red Hat and other vendors are already reviewing the scope of the fix, while Microsoft is urging users to update immediately. Where this is not possible, temporary solutions should be implemented such as disabling esp4/esp6 and related xfrm functions, restricting local access, and strengthening system monitoring.

See also: Vulnerability in Ubuntu Kernel allows Root access

Security countermeasures and the role of AppArmor

Wiz notes that mechanisms like AppArmor can offer partial protection, particularly by restricting unprivileged user namespaces, although they are not a complete solution. The need for layered security becomes even more apparent as the exploit does not require race conditions, reducing the hurdles for an attacker.

Fragnesia: New Linux kernel vulnerability provides root access

Underground threat and zero-day exploits market

The concern is further heightened by reports that a threat actor, going by the name “berz0k,” is advertising a zero-day exploit for Linux LPE on hacking forums with a price tag of up to $170,000. The exploit is said to be based on a TOCTOU vulnerability and allows for persistent local privilege escalation.

See also: Copy Fail: Linux vulnerability allows root access to systems

The emergence of Fragnesia once again highlights the vulnerability of the Linux kernel to complex exploit chains targeting critical memory structures. Although there is no evidence of active exploitation in real-world attacks, the rapid spread of PoC exploits and the existence of commercial demand for zero-day vulnerabilities make it imperative to implement updates immediately. Organizations are urged to act proactively, while strengthening monitoring and access restriction levels, in order to reduce the likelihood of successful privilege escalation on critical systems.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS