Fragnesia (CVE-2026-46300): Frequently asked questions about new Linux Kernel XFRM ESP-in-TCP privilege escalation

2026-05-14T20:52:16Zd84247c399dce3c195777bc34bad319cf3baf94b33b2dadefc78f0fced4a6a65
copy-faildirty-fragesp-in-tcplinux-kernellocal-privilege-escalationmodule-blacklistpatch-releasedproof-of-conceptshared_fragskb_try_coalesceubuntuxfrm

What happened

Fragnesia (CVE-2026-46300) is a high-severity Linux kernel local privilege escalation in the XFRM ESP-in-TCP subsystem disclosed May 13, 2026. A public proof-of-concept exploit exists and has been confirmed working on Ubuntu, though no in-the-wild exploitation has been reported. The bug stems from skb_try_coalesce() failing to propagate the SKBFL_SHARED_FRAG flag (causing file-cache-backed pages to be treated as writable). A kernel patch was released May 13; Dirty Frag fixes do not mitigate this issue, but a module-blacklist mitigation protects against both.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
tenable_blog
Record identifier
d84247c399dce3c195777bc34bad319cf3baf94b33b2dadefc78f0fced4a6a65
Enrichment time
2026-05-14T20:52:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Fragnesia (CVE-2026-46300): Frequently asked questions about new Linux Kernel XFRM ESP-in-TCP privilege escalation · Baitaphish