• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
Sq Magazine LogoSQ Magazine

Smarter Insights for a Fast-Moving Digital World

  • Latest News
  • Statistics
  • About
  • Contact
  • Subscribe
Subscribe
Sq Magazine Logo
  • Latest News
  • Statistics
  • About
  • Contact
  • Subscribe
Subscribe
Home » Cybersecurity

Fragnesia Exploit Threatens Major Linux Distributions

Published on: May 14, 2026, 8:04 AM EDT
Sofia Ramirez
Senior Tech Writer • 637 Articles
Sofia Ramirez is a technology and cybersecurity writer at SQ Magazine. With a keen eye on emerging threats and innovations, she helps reader...
LATEST POSTS:
UK’s Legal AI Sandbox Closes Applications as 83% of Lawyers Flag Hallucination Risk
LibreOffice Fixes Silent RCE Vulnerability, OpenOffice Still Exposed
GMO Research & AI Breach Hits 948,500 infoQ Members
Robert A. Lee
Senior Editor • 464 Articles
Robert A. Lee is a journalist at SQ Magazine who unpacks the fast-moving worlds of gaming and internet trends. He tracks everything from maj...
LATEST POSTS:
Clash Royale Statistics 2026: Revenue, Players and Engagement
Email Security for Small Businesses: The Five Controls That Matter Most
The Growing Role of Device Fingerprinting in Cybersecurity
Fragnesia Exploit Threatens Major Linux Distributions
As Featured In
The New York Times LogoForbes LogoWired LogoDeloitte LogoResearch.com Logo
Share on LinkedIn ChatGPT Perplexity Share on X Share on Facebook

A newly disclosed Linux kernel vulnerability called Fragnesia is raising concerns after researchers confirmed it can give local attackers full root access on several major Linux distributions.

Quick Summary – TLDR:

  • Fragnesia is a newly discovered Linux local privilege escalation vulnerability.
  • The flaw affects the Linux kernel’s XFRM ESP in TCP subsystem.
  • Attackers can gain root privileges by corrupting page cache memory.
  • Multiple Linux vendors including Ubuntu, Debian, Red Hat, and SUSE have released advisories.

What Happened?

Security researchers have disclosed details about a new Linux kernel local privilege escalation vulnerability named Fragnesia, tracked as CVE-2026-46300. The flaw is being described as another member of the recently discovered Dirty Frag family of Linux vulnerabilities.

Researchers say the issue allows unprivileged local attackers to gain root access by modifying read only file contents stored inside the kernel page cache. The vulnerability affects the Linux kernel’s XFRM ESP in TCP implementation, a networking feature used for encrypted traffic handling.

🛑 3rd Linux kernel LPE in just ~2 weeks: Fragnesia (CVE-2026-46300) just dropped.

Attackers can now gain root by corrupting the kernel page cache through a flaw in XFRM ESP-in-TCP.

PoC is public. Major distros have already issued advisories.

Details: https://t.co/s8S9XA3sl1

— The Hacker News (@TheHackersNews) May 14, 2026

A New Variant in the Dirty Frag Family

Fragnesia emerged shortly after researchers disclosed the original Dirty Frag vulnerability. According to security researcher Hyunwoo Kim, the issue appeared as an unintended side effect of patches created for earlier Dirty Frag related flaws.

Research from the V12 security team and cloud security company Wiz revealed that the vulnerability abuses improper handling of shared page fragments during skb coalescing inside the kernel networking stack.

V12 said:

“

This is a separate bug in the ESP/XFRM from Dirty Frag which has received its own patch. However, it is in the same surface and the mitigation is the same as for Dirty Frag.

V12 Security Team

Unlike some previous Linux privilege escalation flaws, researchers noted that Fragnesia does not require race conditions or host level privileges to work. That makes exploitation simpler in certain environments.

How the Exploit Works?

The exploit targets the ESP in TCP subsystem within Linux networking components. Researchers explained that attackers can splice file backed pages into a TCP receive queue before enabling ESP processing.

Once encryption processing begins, the kernel decrypts queued data directly in memory. This behavior allows attackers to corrupt the underlying page cache through controlled AES GCM keystream manipulation.

The proof of concept exploit repeatedly triggers single byte writes into cached file pages. Researchers demonstrated replacing the beginning of the /usr/bin/su binary with a small ELF payload that executes:

  • setresuid(0,0,0)
  • /bin/sh

This eventually gives attackers a root shell without modifying the actual file stored on disk. The malicious changes remain only inside memory through the kernel page cache.

Researchers also confirmed that the exploit uses user namespaces and network namespaces to obtain CAP NET ADMIN privileges within isolated environments.

Newsletter
Don’t chase tech news. We track it for you.

One weekly briefing with the launches, AI developments, and breaches that matter. No filler.

Read by pros at Fortinet, TSMC, Barclays, and Deloitte.

Major Linux Distributions Respond

Several Linux vendors have already released advisories or mitigation guidance related to the vulnerability. Affected distributions include:

  • Ubuntu
  • Debian
  • Red Hat Enterprise Linux
  • SUSE
  • Gentoo
  • AlmaLinux
  • CloudLinux
  • Amazon Linux

Amazon stated that its Linux distribution is not directly affected because it does not provide the vulnerable espintcp module. However, the company said it will still release additional hardening patches as a defense in depth measure.

Microsoft also urged organizations to patch systems as soon as updates become available.

“A patch is available, and while no in the wild exploitation has been observed at this time, we urge users and organizations to apply the patch as soon as possible,” the company said.

Recommended Mitigations

Security experts recommend several temporary mitigation steps until official patches are fully deployed:

  • Disable vulnerable esp4, esp6, and related xfrm/IPsec modules if not required.
  • Restrict unprivileged user namespaces where possible.
  • Monitor systems for suspicious namespace creation and abnormal privilege escalation attempts.
  • Reboot systems or clear page cache memory if exploitation is suspected.

Researchers also noted that AppArmor restrictions used by Ubuntu may provide partial mitigation against successful exploitation attempts.

SQ Magazine Takeaway

I think Fragnesia is another reminder that Linux kernel networking components remain a high value target for attackers. What makes this vulnerability especially worrying is how clean and reliable the exploit appears to be. The fact that attackers can gain root access without touching files on disk makes detection much harder for many security tools. Administrators should treat this as a serious risk and prioritize kernel updates immediately.

This article has been reviewed and fact-checked by Robert A. Lee. SQ Magazine follows strict Publishing Principles and a documented Fact-Check Policy to ensure accuracy, transparency, and editorial independence across all content.

Add SQ Magazine as a Preferred Source on Google for updates! Follow on Google News
Share ChatGPT Perplexity

References

  • CVE-2026-46300 Details
  • Fragnesia: Linux Kernel Local Privilege Escalation via ESP-in-TCP
Sofia Ramirez

Sofia Ramirez

Senior Tech Writer


Sofia Ramirez is a technology and cybersecurity writer at SQ Magazine. With a keen eye on emerging threats and innovations, she helps readers stay informed and secure in today’s fast-changing tech landscape. Passionate about making cybersecurity accessible, Sofia blends research-driven analysis with straightforward explanations; so whether you’re a tech professional or a curious reader, her work ensures you’re always one step ahead in the digital world.

Related Posts

Apache Http Server Vulnerability Patched
Cybersecurity

Critical Apache Bug Enables Remote Code Execution Risk

Qnap Patches 14 Different Vulnerabiltiies
Cybersecurity

QNAP Patches 14 Dangerous Flaws Affecting NAS Systems

Wing Ftp Server Vulnerability Cisa Notification
Cybersecurity

Wing FTP Vulnerability Actively Exploited, CISA Issues Alert

Disclaimer: The content published on SQ Magazine is for informational and educational purposes only. Please verify details independently before making any important decisions based on our content.

Reader Interactions

Leave a Comment Cancel reply

Primary Sidebar

Connect With Us

facebook x linkedin google-news telegram pinterest whatsapp email
google-preferred-source-badge Add as a preferred source on Google

You Should Also Read

Critical Copy Fail Flaw Puts Millions of Linux Systems at Risk
Critical Linux pedit COW Bug Gives Hackers Instant Root Access
Microsoft Confirms Exploitation of Critical Windows Remote Access Flaw in the Wild

Table of Contents

  • Quick Summary – TLDR:
  • What Happened?
  • A New Variant in the Dirty Frag Family
  • How the Exploit Works?
  • Major Linux Distributions Respond
  • Recommended Mitigations
  • SQ Magazine Takeaway

Weekly stats quiz Week 41

How much of a tech geek are you?

5 fast questions from this week's verified industry data. About a minute.

Play the quiz New every Monday

Footer

SQ Magazine Logo

Smarter Insights for a Fast-Moving Digital World

Connect With Us

Follow Us on Google News

Editorial & Trust

  • About
  • Publishing Principles
  • Fact-Check Policy
  • Corrections Policy
  • Ethics Policy
  • Disclaimer
  • Cookie Policy

Worth Checking

  • The Tech Index
  • The Threat Index
  • Social Media Attention Span Stats
  • Instagram Followers Stats
  • Google Usage Stats
  • LLM Hallucination Stats
  • Gen Z Social Media Stats
Contact Us
13570 Grove Dr #189,
Maple Grove, MN 55311,
United States
10 a.m. to 6 p.m. | Every day

Copyright © 2022–2026 SQ Magazine. All Rights Reserved. Powered by the Neural Stack.

  • Privacy Policy
  • Terms
  • Accessibility Statement
Company
  • About Us
  • Our Team
  • Our Mission
  • Core Values
Discover
  • Brand Assets
    Brand Assets
  • Stats Methodology
    Stats Research Process
  • Glossary
    Glossary
Categories
  • Internet
  • Technology
  • Artificial Intelligence
  • Gaming
  • Cryptocurrency
Internet
Average Attention Span Statistics The Cross-Domain Numbers
Average Attention Span Statistics 2026: The Cross-Domain Numbers
How Many Videos Are on YouTube Statistics
How Many Videos Are on YouTube Statistics 2026: Key Data
How Many People Work at WhatsApp
How Many People Work at WhatsApp 2026: Employee Count and History
Spotify Listening Statistics
Spotify Listening Statistics 2026: Average Listening Time
How Many Subscribers Does MrBeast Have
How Many Subscribers Does MrBeast Have in 2026? Channel Growth Statistics
WhatsApp Business Statistics
WhatsApp Business Statistics 2026: Real Market Insights
Technology
Average US Salary Statistics Median Income by Age and State
Average US Salary Statistics 2026: Median Income by Age and State
Aptoide Statistics 2026: Downloads, Users and App Store Share
Aptoide Statistics 2026: Downloads, Users and App Store Share
AppsFlyer Statistics Customers Revenue and Market Position
AppsFlyer Statistics 2026: Customers, Revenue and Market Position
How Many iPhones Has Apple Sold
How Many iPhones Has Apple Sold in 2026? Units Sold by Year
How Many Employees Does Amazon Have
How Many Employees Does Amazon Have 2026: Workforce Growth
Netflix vs. Hulu Statistics
Netflix vs Hulu Statistics 2026: Viewer Growth Data
Artificial Intelligence
AI Search Engine Statistics Usage Market Share and Adoption
AI Search Engine Statistics 2026: Usage, Market Share and Adoption
AI Music Statistics
AI Music Statistics 2026: Generation, Adoption and Industry Impact
AI Coding Statistics
AI Coding Statistics 2026: Adoption, Productivity and Market Data
How Much Content on Social Media Is AI Generated Statistics
How Much Content on Social Media Is AI Generated Statistics 2026: Hidden Truths
ChatGPT vs DeepSeek Statistics
ChatGPT vs DeepSeek Statistics 2026: Users, Benchmarks & Pricing
ChatGPT vs Claude vs Gemini vs Perplexity Statistics
ChatGPT vs Claude vs Gemini vs Perplexity Statistics 2026: Users, Revenue & Market Share
Gaming
Clash Royale Statistics Revenue Players and Engagement
Clash Royale Statistics 2026: Revenue, Players and Engagement
Gaming Statistics
Gaming Statistics 2026: Market Size, Players, Revenue, and Platforms
Roblox vs Minecraft Statistics
Roblox vs Minecraft Statistics 2026: Players, Revenue, Creators
Online Gambling Regulations Statistics
Online Gambling Regulations Statistics 2026: Global Compliance and Enforcement Data
Fantasy Sports Statistics
Fantasy Sports Statistics 2026: Users, Revenue & Trends
Apex Legends Statistics 2026: Players, Revenue, and Esports
Apex Legends Statistics 2026: Players, Revenue, and Esports
Cryptocurrency
How Many Bitcoins Are There
How Many Bitcoins Are There in 2026? Supply, Mined and Remaining Statistics
Stablecoin Usage Statistics
Stablecoin Usage Statistics 2026: Explosive Growth
Cryptocurrency Adoption Statistics
Cryptocurrency Adoption Statistics 2026: Shocking Trends Now
Coinbase Wallet Statistics
Coinbase Wallet Statistics 2026: Users, Security
Dogecoin Statistics 2026: Circulating Supply, Inflation Rate and ETFs
Dogecoin Statistics 2026: Circulating Supply, Inflation Rate and ETFs
BONK Coin Statistics Supply Holders Price and Treasury Data
BONK Coin Statistics 2026: Supply, Holders, Price and Treasury Data
Categories
  • Artificial Intelligence
  • Cybersecurity
  • Technology
  • Internet
  • Cryptocurrency
Artificial Intelligence
Google Launch Synthid Checker Tool
Google Opens SynthID Detector to Public for AI Media Checks
Nano Banana 2 1 Launched Ai Search
Nano Banana 2.1 Lands in Google Search With Big Upgrades
Amazon Strands Deciders 2b Ai Model Jev Killer
Amazon’s Strands Decider 2B Model Targets Faster AI Agents
Gemini 4 Argon Launch
Gemini 4 Argon Launched by Google With Cybersecurity Features
Meta Dispute Muse Private Message Read Claim
Meta Disputes Claim Muse AI Read Private Messages
Openai Dots Gpt 6 1 Sol Launched
OpenAI Launches Dots Agents and GPT-6.1 Sol at DevDay 2026
Cybersecurity
Asos Data Breach Confirmed By Company
ASOS Hack Warning: Customers Urged to Watch for Phishing
Libreoffice Java Malicious Spreadsheets Flaw Patch
LibreOffice Fixes Silent RCE Vulnerability, OpenOffice Still Exposed
Gmo And Mrmax Data Breach
GMO Research & AI Breach Hits 948,500 infoQ Members
Gitlab Cybersecurity Patch Alert
GitLab Warns of Critical RCE Flaw in Self-Hosted AI Gateway
Microsoft X Account Hacked Clippy Crypto
Microsoft X Hackers Push Unauthorized Clippy Crypto Token
Dell Cybersecurity Infrastructure Alert
Dell Patches Two CVSS 10 Container Storage Modules Flaws
Technology
Apple Autumn Launch Surprise
Apple Eyes Surprise Late-October Launch for New Macs
Microsoft Windows Deployment Service Deprecation
Microsoft Will Deprecate Windows Deployment Services After Server 2025
Youtube Custom Feeds With Gemini Ai
YouTube’s AI Feed Builder Changes Video Discovery
Iphone 18 Pro Face Id Bug Reboot Crash
New iPhone 18 Pro Bug Makes Face ID Crash and Reboot
Googlebook With Gemini Ai Launched
Googlebook’s Bold Laptop Launch Starts at $899 in the US
New Samsung Patent Reveals Galaxy Watch Glucose Tracking
New Samsung Patent Reveals Galaxy Watch Glucose Tracking
Internet
Meta Launched Meta One Subscription
Meta One Bundles Instagram, Facebook, WhatsApp Into One AI Subscription
Apple Wallet Ids Launch In Oklahoma
Apple Wallet IDs Launch in Oklahoma in Major Expansion
Meta to Pay 18 Billion in Landmark Teen Safety Deal
Meta to Pay $18 Billion in Landmark Teen Safety Deal
Whatsapp Brings Passkeys 2fa
WhatsApp Hits 1 Billion Passkey Users, Adds 2FA Passwords
Apple Eu App Store Fee Reduction
Apple Sets New EU App Store Fees, Effective October 1
Github Outage Aug 2026
GitHub Down: Outage Hits Thousands of Users Worldwide
Cryptocurrency
Sonic Labs Launch Ussd Stablecoin
Sonic Launches USSD Stablecoin Backed by US Treasuries
Bhutan Moves 12m In Bitcoins
Bhutan Moves $12 Million in Bitcoin from Primary Wallets
Curve Finance Accuses Pancakeswap For Code Stealing
Curve Accuses PancakeSwap of Copying StableSwap Code
Strike Receives Bitlicense In New York
Strike Gets New York BitLicense for Bitcoin Financial Services
Scotiabank Multi Crypto Etf 3iqlogos
Scotiabank Launches Multi Crypto ETF With 3iQ in Canada
Nyse Parent Invests In Okx Crypto Exchange
ICE Invests in OKX to Bridge Crypto and Traditional Finance
Newsletter

Too much tech noise?

We respect your time. One high-signal briefing a week: tech, AI, and security. Nothing else.

Read by pros at Fortinet, TSMC, Barclays, and Deloitte.
Newsletter

The SQ Briefing

We track tech, AI, and security 24/7. You get a 5-minute weekly summary.

Read by pros at Fortinet, TSMC, Barclays, and Deloitte.