Close Menu
    What's Hot

    How Many Electrolytes Should You Be Taking, and Can You Have Too Many?

    Anthropic releases Claude Opus 5 for both AI coding and general office work

    The hacker who humiliated spyware makers and was never caught

    Facebook X (Twitter) Instagram
    Trending
    • How Many Electrolytes Should You Be Taking, and Can You Have Too Many?
    • Anthropic releases Claude Opus 5 for both AI coding and general office work
    • The hacker who humiliated spyware makers and was never caught
    • Anthony Joshua remembers late friends after win over Kristian Prenga sets up Tyson Fury fight and ‘lovely treat’ for fans | Boxing News
    • Appeals Court Upholds Blocks on Trump Order Restricting Mail Voting
    • Want part of Amazon’s $2.5 billion settlement? The deadline is Monday
    • Trump Holds Off on Major War Escalation Against Iran as Advisers Raise Concerns
    • Hundreds of Thousands Flee Fires in France and Spain as Help Pours In
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    New Fragnesia Linux Kernel LPE Grants Root Access via Page Cache Corruption

    adminBy adminMay 14, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    New Fragnesia Linux Kernel LPE Grants Root Access via Page Cache Corruption
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananMay 14, 2026Vulnerability / Linux

    New Fragnesia Linux Kernel LPE Grants Root Access via Page Cache Corruption

    Details have emerged about a new variant of the recent Dirty Frag Linux local privilege escalation (LPE) vulnerability that allows local attackers to gain root access, making it the third such bug to be identified in the kernel within a span of two weeks.

    Codenamed Fragnesia, the security vulnerability is tracked as CVE-2026-46300 (CVSS score: 7.8) and is rooted in the Linux kernel’s XFRM ESP-in-TCP subsystem. It was discovered by researcher William Bowling of the V12 security team.

    “The vulnerability allows unprivileged local attackers to modify read-only file contents in the kernel page cache and achieve root privileges through a deterministic page-cache corruption primitive,” Google-owned Wiz said.

    Cybersecurity

    Advisories have been released by multiple Linux distributions –

    “This is a separate bug in the ESP/XFRM from Dirty Frag which has received its own patch,” V12 said. “However, it is in the same surface and the mitigation is the same as for Dirty Frag. It abuses a logic bug in the Linux XFRM ESP-in-TCP subsystem to achieve arbitrary byte writes into the kernel page cache of read-only files, without requiring any race condition.”

    Fragnesia is similar to Copy Fail and Dirty Frag (aka Copy Fail 2) in that it immediately yields root on all major distributions by achieving a memory write primitive in the kernel and corrupting the page cache memory of the /usr/bin/su binary. A proof-of-concept (PoC) exploit has been released by V12.

    “Customers who have already applied the Dirty Frag mitigation need no further action until patched kernels are released,” CloudLinux maintainers said. Red Hat said it’s performing an assessment to confirm if existing mitigations extend to CVE-2026-46300. 

    Wiz also noted that AppArmor restrictions on unprivileged user namespaces may serve as a partial mitigation, requiring additional bypasses for successful exploitation. However, unlike Dirty Frag, no host-level privileges are required. 

    “A patch is available, and while no in-the-wild exploitation has been observed at this time, we urge users and organizations to apply the patch as soon as possible by running update tools,” Microsoft said. “If patching is not possible at this point, consider applying the same mitigations for Dirty Frag.”

    Cybersecurity

    This includes disabling esp4, esp6, and related xfrm/IPsec functionality, restricting unnecessary local shell access, hardening containerized workloads, and increasing monitoring for abnormal privilege escalation activity.

    The development comes as a threat actor named “berz0k” has been observed advertising on cybercrime forums a zero-day Linux LPE exploit for $170,000, claiming it works on multiple major Linux distributions.

    “The threat actor claims the vulnerability is TOCTOU-based (Time-of-Check Time-of-Use), capable of stable local privilege escalation without causing system crashes, and leverages a shared object (.so) payload dropped into the /tmp directory,” ThreatMon said in a post on X.

    access cache corruption Fragnesia Grants Kernel Linux LPE Page root
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleThe creative risk of letting AI do all the work
    Next Article Why ‘Smart’ Products Have Started to Look Like the Dumb Choice
    admin
    • Website

    Related Posts

    Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

    July 25, 2026

    DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

    July 25, 2026

    Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

    July 25, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    How Many Electrolytes Should You Be Taking, and Can You Have Too Many?

    Anthropic releases Claude Opus 5 for both AI coding and general office work

    The hacker who humiliated spyware makers and was never caught

    Anthony Joshua remembers late friends after win over Kristian Prenga sets up Tyson Fury fight and ‘lovely treat’ for fans | Boxing News

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by