Fragnesia: New Linux kernel LPE bug was spawned by Dirty Frag patch (CVE-2026-46300)

2026-05-14T14:51:47Ze14243512e64fb4221a84388896e7fc96559406a080659898950cebfece1b533
CVE-2026-43284CVE-2026-46300dirty-fraghelpnetsecuritykernel-patchlinuxlinux-kernellocal-privilege-escalationlpesecurity-advisoryvulnerabilityxfrm-ESP

What happened

Researchers disclosed a new Linux kernel local privilege escalation (LPE) vulnerability, CVE-2026-46300 (“Fragnesia”). The bug is in the xfrm-ESP subsystem and is in the same class as the recently reported Dirty Frag issues; Fragnesia was reportedly “accidentally activated” by a patch for CVE-2026-43284. The flaw can enable local attackers to elevate privileges — users and administrators should apply vendor/kernel updates or mitigations as soon as patches are available.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
e14243512e64fb4221a84388896e7fc96559406a080659898950cebfece1b533
Enrichment time
2026-05-14T14:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Fragnesia: New Linux kernel LPE bug was spawned by Dirty Frag patch (CVE-2026-46300) · Baitaphish