CVE-2026-46300Disclosure(linux / linux_kernel)

CRITICALCVSS 7.8 · HIGH

Exploitation observed; activity peaked at 74 mentions and remains active

Immediate actions

  • Patch linux linux_kernel systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() can attach paged frags from @from to @to. If @from has SKBFL_SHARED_FRAG set, the resulting @to skb can contain the same externally-owned or page-cache-backed frags, but the shared-frag marker is currently lost. That breaks the invariant relied on by later in-place writers. In particular, ESP input checks skb_has_shared_frag() before deciding whether an uncloned nonlinear skb can skip skb_cow_data(). If TCP receive coalescing has moved shared frags into an unmarked skb, ESP can see skb_has_shared_frag() as false and decrypt in place over page-cache backed frags. Propagate SKBFL_SHARED_FRAG when skb_try_coalesce() transfers paged frags. The tailroom copy path does not need the marker because it copies bytes into @to's linear data rather than transferring frag descriptors.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787CWE-123

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Active exploitation appears in 7 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 198 mentions across 39 observed days

What's happening

  • Active exploitation reported across 7 signals
  • Exploit tool or code specified in 19 signals
  • PoC mentioned or linked in 49 signals
  • Patch or workaround mentioned in 74 signals
  • Technical details provided in 130 signals
  • Disclosure: 66 classified signals
  • General: 46 classified signals
  • Peaked 37d ago at 74 mentions (2026-05-14); latest day: 1
  • 198 total mentions across 39 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline198 mentions / 39d
019375674Mentions · 2026-05-13: 13Mentions · 2026-05-14: 74Mentions · 2026-05-15: 29Mentions · 2026-05-16: 11Mentions · 2026-05-17: 5Mentions · 2026-05-18: 11Mentions · 2026-05-19: 5Mentions · 2026-05-20: 8Mentions · 2026-05-21: 2Mentions · 2026-05-22: 3Mentions · 2026-05-23: 2Mentions · 2026-05-24: 2Mentions · 2026-05-25: 2Mentions · 2026-05-26: 1Mentions · 2026-05-27: 2Mentions · 2026-05-28: 1Mentions · 2026-05-29: 2Mentions · 2026-05-30: 2Mentions · 2026-05-31: 1Mentions · 2026-06-01: 1Mentions · 2026-06-02: 1Mentions · 2026-06-03: 1Mentions · 2026-06-04: 2Mentions · 2026-06-08: 1Mentions · 2026-06-11: 1Mentions · 2026-06-12: 1Mentions · 2026-06-24: 1Mentions · 2026-06-26: 1Mentions · 2026-06-27: 1Mentions · 2026-07-02: 1Mentions · 2026-08-01: 1Mentions · 2026-08-03: 1Mentions · 2026-08-15: 1Mentions · 2026-08-16: 1Mentions · 2026-08-25: 1Mentions · 2026-08-30: 2Mentions · 2026-09-11: 1Mentions · 2026-09-13: 1Mentions · 2026-09-30: 1PoC Mentioned / Linked · 2026-05-13: 3PoC Mentioned / Linked · 2026-05-14: 16PoC Mentioned / Linked · 2026-05-15: 11PoC Mentioned / Linked · 2026-05-16: 3PoC Mentioned / Linked · 2026-05-17: 2PoC Mentioned / Linked · 2026-05-18: 4PoC Mentioned / Linked · 2026-05-19: 2PoC Mentioned / Linked · 2026-05-20: 1PoC Mentioned / Linked · 2026-05-29: 1PoC Mentioned / Linked · 2026-06-04: 1PoC Mentioned / Linked · 2026-06-12: 1PoC Mentioned / Linked · 2026-06-26: 1PoC Mentioned / Linked · 2026-08-01: 1PoC Mentioned / Linked · 2026-08-16: 1PoC Mentioned / Linked · 2026-08-25: 1Exploit Tool / Code · 2026-05-13: 1Exploit Tool / Code · 2026-05-14: 4Exploit Tool / Code · 2026-05-15: 4Exploit Tool / Code · 2026-05-16: 1Exploit Tool / Code · 2026-05-17: 2Exploit Tool / Code · 2026-05-19: 2Exploit Tool / Code · 2026-05-20: 1Exploit Tool / Code · 2026-05-29: 1Exploit Tool / Code · 2026-06-26: 1Exploit Tool / Code · 2026-08-01: 1Exploit Tool / Code · 2026-08-15: 1Active Exploitation · 2026-05-14: 1Active Exploitation · 2026-05-15: 4Active Exploitation · 2026-05-16: 1Active Exploitation · 2026-09-13: 1Patch / Workaround · 2026-05-13: 7Patch / Workaround · 2026-05-14: 28Patch / Workaround · 2026-05-15: 12Patch / Workaround · 2026-05-16: 4Patch / Workaround · 2026-05-17: 2Patch / Workaround · 2026-05-18: 2Patch / Workaround · 2026-05-19: 1Patch / Workaround · 2026-05-20: 5Patch / Workaround · 2026-05-21: 2Patch / Workaround · 2026-05-23: 1Patch / Workaround · 2026-05-24: 1Patch / Workaround · 2026-05-27: 1Patch / Workaround · 2026-05-30: 1Patch / Workaround · 2026-06-02: 1Patch / Workaround · 2026-06-03: 1Patch / Workaround · 2026-06-04: 2Patch / Workaround · 2026-06-24: 1Patch / Workaround · 2026-06-26: 1Patch / Workaround · 2026-08-03: 1Technical Details · 2026-05-13: 6Technical Details · 2026-05-14: 55Technical Details · 2026-05-15: 21Technical Details · 2026-05-16: 5Technical Details · 2026-05-17: 5Technical Details · 2026-05-18: 7Technical Details · 2026-05-19: 5Technical Details · 2026-05-20: 3Technical Details · 2026-05-24: 2Technical Details · 2026-05-25: 2Technical Details · 2026-05-26: 1Technical Details · 2026-05-27: 1Technical Details · 2026-05-29: 1Technical Details · 2026-05-31: 1Technical Details · 2026-06-04: 2Technical Details · 2026-06-08: 1Technical Details · 2026-06-11: 1Technical Details · 2026-06-12: 1Technical Details · 2026-06-24: 1Technical Details · 2026-06-26: 1Technical Details · 2026-08-01: 1Technical Details · 2026-08-03: 1Technical Details · 2026-08-15: 1Technical Details · 2026-08-16: 1Technical Details · 2026-08-25: 1Technical Details · 2026-08-30: 1Technical Details · 2026-09-11: 1Technical Details · 2026-09-13: 105-1305-1605-1905-2205-2505-2805-3106-0306-1106-2608-0108-1609-1109-30
Signal classification6 categories
Disclosure
6633.5%
General
4623.4%
Patch
4422.3%
PoC
2914.7%
Exploit
73.6%
Active Exploitation
52.5%
Referenced assets122 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-1313
Disclosure2General5Patch5PoC1
2026-05-1474
Active Exploitation1Disclosure33Exploit1General13Patch16PoC10
2026-05-1529
Active Exploitation2Disclosure7Exploit2General6Patch6PoC6
2026-05-1611
Active Exploitation1Disclosure5General1Patch1PoC3
2026-05-175
Disclosure2General1PoC2
2026-05-1811
Disclosure7General2Patch1PoC1
2026-05-195
Disclosure3PoC2
2026-05-208
Disclosure1General1Patch5PoC1
2026-05-212
Patch2
2026-05-223
General3
2026-05-232
General1Patch1
2026-05-242
Disclosure1Patch1
2026-05-252
Disclosure1General1
2026-05-261
General1
2026-05-272
General1Patch1
2026-05-281
General1
2026-05-292
Exploit1General1
2026-05-302
General1Patch1
2026-05-311
Disclosure1
2026-06-011
General1
2026-06-021
Patch1
2026-06-031
Patch1
2026-06-042
General1Patch1
2026-06-081
General1
2026-06-111
Disclosure1
2026-06-121
PoC1
2026-06-241
Patch1
2026-06-261
Exploit1
2026-06-271
Disclosure1
2026-07-021
General1
2026-08-011
Exploit1
2026-08-031
General1
2026-08-151
Exploit1
2026-08-161
PoC1
2026-08-251
PoC1
2026-08-302
General2
2026-09-111
Disclosure1
2026-09-131
Active Exploitation1
Full discourse20 posts
  • hsn今天吃什么@hsn8086k
    General

    2026 Linux 重置密码教程大全 - Dirty Cow (CVE-2016-5195) - Dirty Pipe (CVE-2022-0847) - io_uring UAF (CVE-2022-2602) - Copy Fail (CVE-2026-31431) - io_uring ZCRX freelist (CVE-2026-43121) - Dirty Frag (CVE-2026-43284 CVE-2026-43500) - Fragnesia (CVE-2026-46300)

    Post summary

    The post enumerates several Linux CVEs and associated exploit names as part of a password-reset tutorial, but it does not provide PoCs, exploit code, patch details, or evidence of active exploitation.

    17193111.1K50579.9K
    2.3K followersView on X
  • Microsoft Threat Intelligence@MsftSecIntel
    Patch

    A new variant of the recent Dirty Frag vulnerability, named Fragnesia (CVE-2026-46300), has been discovered in the Linux XFRM ESP-in-TCP subsystem. Similar to Dirty Frag, Fragnesia exploits a vulnerability in the XFRM ESP-in-TCP subsystem to achieve a memory write primitive in the kernel. The primitive is then used to corrupt the page cache memory of the [/]usr[/]bin[/]su binary, which in turn leads to launching a shell with root privilege. Note that exploitation is not constrained to use the [/]usr[/]bin[/]su binary; it can modify any file readable by the user, including [/]etc[/]passwd. A patch is available, and while no in-the-wild exploitation has been observed at this time, we urge users and organizations to apply the patch as soon as possible by running update tools. If patching is not possible at this point, consider applying the same mitigations for Dirty Frag, such as: - Assess whether esp4, esp6, and related xfrm/IPsec functionality can be temporarily disabled safely - Restrict unnecessary local shell access - Harden containerized workloads - Increase monitoring for abnormal privilege escalation activity Microsoft Defender detects and blocks known Fragnesia proof-of-concept (PoC) exploit codes using existing detections for Dirty Frag, such as Trojan:Linux/DirtyFrag.DA!MTB or Trojan:Linux/DirtyFrag.Z!MTB. Microsoft continues to investigate the issue, and we'll share updates as more information becomes available.

    Post summary

    A new variant of Dirty Frag, Fragnesia (CVE‑2026‑46300), exploits a memory write primitive to corrupt the page cache of /usr/bin/su and can grant root privileges. A patch is available, with additional mitigations advised, and no wild exploitation has been reported.

    2416714954334106.2K
    196.2K followersView on X
  • hsn今天吃什么@hsn8086k
    General

    Linux 重置密码大全 - Dirty Cow (CVE-2016-5195) - Dirty Pipe (CVE-2022-0847) - io_uring UAF (CVE-2022-2602) - Copy Fail (CVE-2026-31431) - io_uring ZCRX freelist (CVE-2026-43121) - Dirty Frag (CVE-2026-43284 CVE-2026-43500) - Fragnesia (CVE-2026-46300) -PinTheft (CVE-2026-43494)

    Post summary

    The entry lists several Linux kernel CVEs without offering further details, evidence, or actionable information.

    43118972036546.3K
    2.3K followersView on X
  • Het Mehta@hetmehtaa
    General

    Them: Linux is most secure OS Me: Yes - Dirty Cow (CVE-2016-5195) - Dirty Pipe (CVE-2022-0847) - io_uring UAF (CVE-2022-2602) - Copy Fail (CVE-2026-31431) - io_uring ZCRX freelist (CVE-2026-43121) - Dirty Frag (CVE-2026-43284 CVE-2026-43500) - Fragnesia (CVE-2026-46300)

    Post summary

    The message lists several Linux CVEs but provides no additional technical, exploit, or remediation details.

    566618598272159.8K
    42.2K followersView on X
  • AlmaLinux@AlmaLinux
    Disclosure

    🚨 A third Linux kernel local-root flaw has been disclosed: Fragnesia. 🚨 Like Copy Fail & Dirty Frag, Fragnesia gives root on all major distributions. Every supported AlmaLinux release is affected. Help us test the patched kernels: https://almalinux.org/blog/2026-05-13-fragnesia-cve-2026-46300/ https://t.co/g0b7Hwrcnv

    Post summary

    A new Linux kernel local‑root vulnerability (Fragnesia/CVE‑2026‑46300) affecting AlmaLinux and other major distributions has been disclosed, with a patch available via the linked AlmaLinux blog.

    101511862914756.7K
    12.4K followersView on X
  • hito@_hito_
    General

    記憶バッファに収まらないんですが…… ・Copy Fail / CVE-2026-31431 ・Dirty Frag / CVE-2026-43284, CVE-2026-43500 ・Fragnesia / CVE-2026-46300

    Post summary

    The post lists several CVE identifiers with a brief mention of a memory buffer issue but offers no additional context, details, or actionable information.

    236323712028.8K
    2.2K followersView on X
  • The Hacker News@TheHackersNews
    PoC

    🛑 3rd Linux kernel LPE in just ~2 weeks: Fragnesia (CVE-2026-46300) just dropped. Attackers can now gain root by corrupting the kernel page cache through a flaw in XFRM ESP-in-TCP. PoC is public. Major distros have already issued advisories. Details: https://thehackernews.com/2026/05/new-fragnesia-linux-kernel-lpe-grants.html

    Post summary

    CVE-2026-46300, a Linux kernel local privilege escalation, has been disclosed with a public PoC and advisories from major distros, but no evidence of active exploitation yet.

    75961995331.1K
    1.9M followersView on X
  • yousukezan@yousukezan
    Exploit

    Linuxカーネルの権限昇格の脆弱性「DirtyClone」が公開され、JFrog Security Researchは6月25日に動作するエクスプロイトを公開した。CVE-2026-43503が割り当てられており、ローカルユーザーがroot権限を取得できる可能性がある。 原因は、ネットワークパケットを複製する際に、ファイルと共有されているメモリを示すフラグが失われることにある。攻撃者はIPsec経由で複製されたパケットを利用し、メモリ上に読み込まれた/usr/bin/suなどの実行ファイルを書き換え、次回実行時にroot権限を取得できる。 変更はディスク上のファイルには反映されず、カーネルのページキャッシュ内だけで発生するため、ファイル整合性チェックでは検出されず、再起動すると元に戻るという。 攻撃にはCAP_NET_ADMIN権限が必要だが、DebianやFedoraではデフォルトで有効な非特権ユーザー名前空間を利用して取得できる。一方、Ubuntu 24.04以降ではAppArmorにより標準的な攻撃手法は制限される。 DirtyCloneは、Copy Fail(CVE-2026-31431)、DirtyFrag(CVE-2026-43284、CVE-2026-43500)、Fragnesia(CVE-2026-46300)に続く4件目の関連脆弱性となる。修正は5月21日にメインラインへ取り込まれ、Linux v7.1-rc5以降および安定版・LTSへバックポートされている。更新できない場合は、非特権ユーザー名前空間を無効化するか、IPsec関連モジュールを無効化することで攻撃面を減らせるとしている。 https://thehackernews.com/2026/06/new-dirtyclone-linux-kernel-flaw-lets.html

    Post summary

    DirtyClone is a Linux kernel privilege‑escalation flaw for which a working local exploit was publicly released. Patches are available and mitigations such as disabling user‑namespace or IPsec modules are recommended.

    0464115679.5K
    14.8K followersView on X
  • Clandestine@akaclandestine
    PoC

    Threat Intelligence Alert | In-Depth Technical Analysis: New Fragnesia Variant (fragnesia-5db89c99566fc) — Bypass of CVE-2026-46300 Patch V12 Security has released a fully functional PoC for a new bypass of the previously merged fix (commit f84eca581739) for CVE-2026-46300 (Fragnesia). This marks the latest iteration in the Dirty Frag family of Linux kernel Local Privilege Escalation (LPE) vulnerabilities targeting the XFRM ESP-in-TCP subsystem. 🔍 Root Cause (net/core/skbuff.c — skb_segment()) When constructing GSO segments from an skb that contains a frag_list, the SKBFL_SHARED_FRAG flag is propagated only from the head skb. Members of the frag_list carrying page-cache-backed fragments with the flag set lose this marker during segmentation. Consequence: the resulting segments bypass the skip_cow() check inside esp_input(), enabling AES-GCM decryption in-place directly over page cache pages — the exact same powerful primitive used by previous Dirty Frag and Fragnesia exploits. 🔬 Deterministic Trigger Chain 1. Three network namespaces connected via veth pairs (sender → forwarder → receiver). 2. Sender performs send() + splice() (from the same read-only file) on the identical TCP connection. 3. GRO coalescing on the forwarder merges both packets within the same NAPI poll: • send() → head skb (no flag) • splice() → frag_list (with SKBFL_SHARED_FRAG) 4. GSO is disabled on the forwarder’s egress interface, forcing skb_segment(). 5. The flag is lost on the generated segments. 6. Segments arrive at the receiver with ESP-in-TCP active, allowing controlled 1-byte arbitrary writes into the page cache via the AES-GCM keystream. The exploit iterates a small ELF payload, automatically locates and overwrites a SUID-root binary (with automatic backup), and spawns a root shell. The page cache modification is non-persistent on disk and can be cleared with drop_caches. ✅ Full working PoC (including skb_segment_exploit.c, Makefile and detailed README): https://github.com/v12-security/pocs/tree/main/fragnesia-5db89c99566fc 📌 References: • Original Fragnesia (CVE-2026-46300): https://github.com/v12-security/pocs/blob/main/fragnesia/README.md • V12 Security: https://v12.sh ❌ No patch is currently available in mainline or netdev trees for this bypass. Immediate Mitigation (identical to Dirty Frag / Fragnesia): • sudo modprobe -r esp4 esp6 rxrpc • Blacklist the modules esp4, esp6 and rxrpc System administrators and SOC teams should apply this mitigation immediately and monitor for XFRM/ESP module loading. #Linux #KernelLinux #CVE202646300 #Fragnesia #DirtyFrag #LPE #PrivilegeEscalation #XFRM #ESPinTCP #LinuxKernel #CyberSecurity #InfoSec #ThreatIntelligence #Vulnerability #OSINT #LinuxSecurity #KernelSecurity #RedTeam #BlueTeam #SysAdmin #DevOps #VulnMgmt #CyberThreat

    Post summary

    The alert announces a fully functional PoC for a new bypass of CVE‑2026‑46300, detailing technical root cause, trigger chain, and providing mitigation steps and code repository links.

    2371111759.9K
    62.5K followersView on X
  • Sekurak@Sekurak
    Disclosure

    Uwaga. Frangnesia (CVE-2026-46300) Kolejna poważna podatność w jądrze Linuxa. Local Privilege Escalation do root. Temat podobny do podatności copy fail/dirty frag.

    Post summary

    The text announces CVE‑2026‑46300, a new kernel-level LPE vulnerability in Linux, without mentioning a PoC, exploit code, or patch.

    111273188.3K
    43.9K followersView on X
  • Jordan Nanos@JordanNanos
    General

    Good stuff from Dwark!! - dwark says Astra was involved in the attack on huggingface but OpenAI says it was 5.6 sol, someone is wrong here - to escalate within OpenAI infrastructure the black hat talk specifically says they used a Linux kernel exploit that has a public CVE, “pte_physroot", which I am speculating is Fragnesia: CVE-2026-46300, published May 23 - why is everyone glossing over the fact that OpenAI’s agents were found to be coordinating with agents from another lab??

    Post summary

    The post speculates that a Linux kernel CVE (CVE-2026-46300) was used in an OpenAI infrastructure attack, but it provides no concrete evidence, technical details, or mitigation information.

    1021632418.7K
    5.5K followersView on X
  • 情報の灯台@joho_no_todai
    Disclosure

    Fragnesia公開、Linux LPE 2週で3件目 Linuxカーネルにローカル権限昇格の脆弱性「Fragnesia」(CVE-2026-46300)が公開された。 Copy Fail、Dirty Fragに続き2週間で3つ目。 3件とも、ページキャッシュへの不正書き込みという同じバグクラスに属する。 Dirty Fragを発見したヒョンウ・キム氏は、Fragnesiaを「Dirty Frag修正パッチの意図しない副作用」と説明している。 修正そのものが、次の穴を露わにしている。 https://joho-todai.com/fragnesia-released-linux-lpe-third-exploit/

    Post summary

    The article announces the public release of the Fragnesia CVE‑2026‑46300 local privilege escalation vulnerability, provides technical details, links to a PoC/exploit, and discusses the patch that inadvertently creates another flaw.

    01824573.2K
    11.1K followersView on X
  • yousukezan@yousukezan
    Patch

    AIが見つけたLinuxカーネルの致命的脆弱性『Fragnesia』(CVE-2026-46300)の深層:Dirty Fragの再来と対策|you2h https://zenn.dev/you2h/articles/20260520-etc-modprobe-d-disable-esp-con-94b8dde2 #zenn

    Post summary

    The text refers to a newly discovered Linux kernel vulnerability and highlights the availability of countermeasures or patches.

    06037173.3K
    14.5K followersView on X
  • AlmaLinux@AlmaLinux
    Patch

    ICYMI, Fragnesia (CVE-2026-46300) is a third recently disclosed Linux kernel local-root flaw. Every supported AlmaLinux release is affected, so patched kernels have been rolled out to production repositories/mirrors. https://almalinux.org/blog/2026-05-13-fragnesia-cve-2026-46300/?utm_medium=social&utm_source=twitter

    Post summary

    The tweet notes that CVE-2026-46300 is a Linux kernel local‑root flaw affecting all supported AlmaLinux releases, with patches already deployed, but no PoC, exploit, or active exploitation is reported.

    0503152.4K
    12.4K followersView on X
  • Manabu Ori@orimanabu
    General

    Dirty Fragの別のvariant "Fragnesia" に関するRed Hat製品の情報についてはこちらをご参照ください (今はまだほとんど情報がないですが随時更新されます) https://access.redhat.com/security/cve/cve-2026-46300

    Post summary

    The post simply points to the Red Hat security page for CVE‑2026‑46300, noting that detailed information is scarce but will be updated.

    1802292.4K
    1.3K followersView on X
  • hito@_hito_
    General

    Linuxのカーネルまわりの脆弱性(最近のやつ)の整理(as of 5月18日) ・Copy Fail / CVE-2026-31431 ・Dirty Frag (Copy Fail 2) / CVE-2026-43284, CVE-2026-43500 ・Fragnesia / CVE-2026-46300 ・DirtyDecrypt (Fragnesia亜種) LPE連打が厄介。

    Post summary

    A brief list of recent Linux kernel CVEs is provided, but no PoC, exploit, patch, or detailed technical information is included.

    01211872.8K
    2.2K followersView on X
  • Brad Spengler@spendergrsec
    General

    Anyway, totally unrelated, was just thinking about the current CVE system where you have exploits coming out weeks before a CVE number or description: https://lore.kernel.org/linux-cve-announce/2026052311-CVE-2026-46300-27bc@gregkh/T/#u https://lore.kernel.org/linux-cve-announce/2026052309-CVE-2026-43503-b134@gregkh/T/#u

    Post summary

    The user comments on the lag between exploit release and CVE assignment, citing two recent kernel CVE announcements without providing technical or exploit details.

    10126948.2K
    7.0K followersView on X
  • MigawariIV@strinsert1Na
    General

    また universal な linux LPE だ...... (Fragnesia, CVE-2026-46300) 一応 Dirty Frag で対応していた人たちは緩和策ほぼ同じだろうからそれが救いか......

    Post summary

    The post comments on a universal Linux local privilege escalation (CVE-2026-46300) and notes that users who mitigated via Dirty Frag likely have a similar workaround, but provides no PoC, exploit code, or patch details.

    0302576.3K
    5.1K followersView on X
  • hito@_hito_
    Disclosure

    Linuxのカーネルまわりの脆弱性(最近のやつ)の整理: ・Copy Fail / CVE-2026-31431 ・Dirty Frag / CVE-2026-43284, CVE-2026-43500 ・Fragnesia / CVE-2026-46300 ・Fragnesia亜種 / CVE未採番 <- 5/16(日本時間)に登場した新種 たいていのディストリビューションで対処済みなのはFragnesiaまでで、最新のやつはどうなってるかケースバイケースです……。

    Post summary

    The post lists recent Linux kernel CVEs, noting that most distributions have patched up to the Fragnesia vulnerability, with newer CVEs still pending patch status assessment.

    0802061.0K
    2.2K followersView on X
  • The Hacker News@TheHackersNews
    Exploit

    What makes Fragnesia (CVE-2026-46300) deadlier than most LPEs: • Deterministic logic bug (no race condition) • Unprivileged user → arbitrary byte writes into kernel page cache • Directly overwrites read-only files like /usr/bin/su • One clean PoC run = instant root PoC already public.

    Post summary

    CVE‑2026‑46300 is a deterministic logic bug that permits an unprivileged user to overwrite read‑only files such as /usr/bin/su and gain root with a single PoC run; a public PoC demonstrates a functional exploit.

    1612057.9K
    1.9M followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.1--
OSlinuxlinux_kernel7.1--
OSlinuxlinux_kernel7.1--
OSlinuxlinux_kernel7.1--

Explore more