Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Fragnesia: New Linux kernel LPE bug was spawned by Dirty Frag patch (CVE-2026-46300)
    Cybersecurity

    Fragnesia: New Linux kernel LPE bug was spawned by Dirty Frag patch (CVE-2026-46300)

    adminBy adminMay 14, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Fragnesia: New Linux kernel LPE bug was spawned by Dirty Frag patch (CVE-2026-46300)
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Researchers have found and disclosed yet another local privilege escalation (LPE) vulnerability in the Linux kernel: CVE-2026-46300, aka “Fragnesia”.

    Fragnesia CVE-2026-46300 Linux LPE

    The flaw is in the same class of vulnerabilities as the recently disclosed Dirty Frag bug(s).

    Like Dirty Frag, it affects the same Linux module (xfrm-ESP). In fact, according to Dirty Frag discoverer Hyunwoo Kim, Fragnesia was “accidentally activated” by the patch fixing one of the original Dirty Frag vulnerabilities (i.e., CVE-2026-43284).

    CVE-2026-46300 explained

    Fragnesia was discovered by William Bowling of Zellic.io, with the help of the company’s AI-agentic software auditing tool.

    The research team published a short technical explainer and proof-of-concept exploit code.

    As Wiz researchers helpfully explained, Fragnesia allows unprivileged local attackers to modify read-only file contents in the kernel page cache, and “through a deterministic page-cache corruption primitive,” achieve root privileges.

    Patches and mitigations for Fragnesia

    Like Copy Fail and Dirty Frag before it, Fragnesia is less of a risk for single-user workstations and single-tenant servers than for shared Linux hosts (where multiple users share a kernel), container clusters (where the page cache is shared across the host), CI runners and build farms, and cloud SaaS solutions running user code.

    Linux admins should apply vendor kernel patches when they become available. In the meantime, they should disable/denylist or unload the vulnerable modules (for both Fragnesia and DirtyFrag: esp4, esp6, rxrpc) to mitigate the risk of exploitation.

    Some Linux distributions have already relased kernel patches, namely AlmaLinux and CloudLinux.

    “The exploit can modify legitimate system binaries (the public PoC overwrites /usr/bin/su) in the page cache as part of gaining root, so applying the mitigation alone is not enough on systems that may have been targeted before the mitigation was in place,” the CloudLinux team explained.

    “After mitigating, drop the page cache to force a reload from disk [by running the following command: sudo sh -c “echo 3 > /proc/sys/vm/drop_caches”].”

    Microsoft’s threat analysts also pointed out that exploitation is “not constrained to use the [/usr/bin/su] binary,” and that attackers “can modify any file readable by the user, including [/etc/passwd].”

    They also added that there is currently no evidence pointing to in-the-wild exploitation of Fragnesia.

    Copy Fail, on the other hand, has been added to CISA’s Known Exploited Vulnerabilities catalog earlier this month.

    Kernel patches for Copy Fail are now widely available, but for a temporary mitigation admins can denylist or unload the algif_aead module.

    Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

    bug CVE202646300 Dirty Frag Fragnesia Kernel Linux LPE Patch spawned
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous Article46 Father’s Day Messages & Quotes (+Templates)
    Next Article Network outages, power failures strain data center resiliency
    admin
    • Website

    Related Posts

    Encryption Consulting launches CertSecure Manager v3.3 with zero-touch certificate renewals

    May 20, 2026

    GitHub confirms breach of 3,800 repos via malicious VSCode extension

    May 20, 2026

    Grafana GitHub Breach Exposes Source Code via TanStack npm Attack

    May 20, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Mueller Explains Why Google Uses Markdown On Dev Docs

    May 21, 2026

    Google Marketing Live 2026: Everything you need to know

    May 21, 2026

    Google unveils Gemini 3.5 Flash and a redesigned ‘intelligent Search box’

    May 21, 2026

    12 Awesome Custom Google Analytics Reports Created by the Experts

    May 20, 2026
    Categories
    • Blogging (82)
    • Cybersecurity (1,955)
    • Privacy & Online Earning (223)
    • SEO & Digital Marketing (1,214)
    • Tech Tools & Mobile / Apps (1,796)
    • WiFi / Internet & Networking (306)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Mueller Explains Why Google Uses Markdown On Dev Docs

    May 21, 2026

    Google Marketing Live 2026: Everything you need to know

    May 21, 2026

    Google unveils Gemini 3.5 Flash and a redesigned ‘intelligent Search box’

    May 21, 2026
    Most Popular
    • Mueller Explains Why Google Uses Markdown On Dev Docs
    • Google Marketing Live 2026: Everything you need to know
    • Google unveils Gemini 3.5 Flash and a redesigned ‘intelligent Search box’
    • 12 Awesome Custom Google Analytics Reports Created by the Experts
    • Selector targets the network visibility gap in multi-cloud infrastructure
    • How to Persuade Your Boss to Send You to Ahrefs Evolve in San Diego
    • Key AEO & Content Trends for 2026
    • Google adds llms.txt check to Chrome Lighthouse
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.