Fragnesia (CVE-2026-46300): Frequently asked questions about new Linux Kernel XFRM ESP-in-TCP privilege escalation
2026-05-14T20:52:16Z•d84247c399dce3c195777bc34bad319cf3baf94b33b2dadefc78f0fced4a6a65
copy-faildirty-fragesp-in-tcplinux-kernellocal-privilege-escalationmodule-blacklistpatch-releasedproof-of-conceptshared_fragskb_try_coalesceubuntuxfrm
What happened
Fragnesia (CVE-2026-46300) is a high-severity Linux kernel local privilege escalation in the XFRM ESP-in-TCP subsystem disclosed May 13, 2026. A public proof-of-concept exploit exists and has been confirmed working on Ubuntu, though no in-the-wild exploitation has been reported. The bug stems from skb_try_coalesce() failing to propagate the SKBFL_SHARED_FRAG flag (causing file-cache-backed pages to be treated as writable). A kernel patch was released May 13; Dirty Frag fixes do not mitigate this issue, but a module-blacklist mitigation protects against both.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- tenable_blog
- Record identifier
- d84247c399dce3c195777bc34bad319cf3baf94b33b2dadefc78f0fced4a6a65
- Enrichment time
- 2026-05-14T20:52:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.