#Fragnesia
The skb that wasn’t freed - the Fragnesia primitive via Open vSwitch.

#Doyensec found a local priv. esc. affecting default Arch, Fedora, Debian, Amazon #Linux & RHEL. Read how a missing flag allows an unprivileged user to gain root access.

blog.doyensec.com/2026/09/17/o...

#appsec #security
September 18, 2026 at 2:39 PM
Fragnesia primitive via Open vSwitch. Deterministic local privilege escalation.
Fragnesia primitive via Open vSwitch. Deterministic local privilege escalation.
blog.doyensec.com
September 17, 2026 at 9:39 AM
[RSS] Fragnesia primitive via Open vSwitch. Deterministic local privilege escalation.


blog.doyensec.com ->


Original->
September 17, 2026 at 8:39 AM
The skb that wasn't freed - the Fragnesia primitive via Open vSwitch https://lobste.rs/s/q6f60y ##security ##linux
The skb that wasn't freed - the Fragnesia primitive via Open vSwitch
blog.doyensec.com
September 17, 2026 at 8:45 AM
Fragnesia primitive via Open vSwitch. Deterministic local privilege escalation.
The skb that wasn't freed - the Fragnesia primitive via Open vSwitch · Doyensec's Blog
blog.doyensec.com
September 17, 2026 at 7:13 AM
The skb that wasn't freed - the Fragnesia primitive via Open vSwitch https://blog.doyensec.com/2026/09/17/ovs.html
The skb that wasn't freed - the Fragnesia primitive via Open vSwitch · Doyensec's Blog
The skb that wasn't freed - the Fragnesia primitive via Open vSwitch
blog.doyensec.com
September 17, 2026 at 6:49 AM
GKE Fragnesia Vulnerability CVE-2026-46300: Affected Nodes, Fixed Versions & Mitigations

GKE Fragnesia CVE-2026-46300 is a Linux-kernel container breakout affecting GKE Standard clusters with Ubuntu nodes. See affected environments, fixed GKE versions and practical mitigations.
GKE Fragnesia Vulnerability CVE-2026-46300: Affected Nodes, Fixed Versions & Mitigations
GKE Fragnesia CVE-2026-46300 is a Linux-kernel container breakout affecting GKE Standard clusters with Ubuntu nodes. See affected environments, fixed GKE versions and practical mitigations.
digitalpulsebrief.com
September 16, 2026 at 9:59 AM
CVE-2026-46300 Fragnesia: Linux Kernel Bug Exposed on GKE Since May
CVE-2026-46300 Fragnesia: Linux Kernel Bug Exposed on GKE Since May
Fragnesia exploits a flaw in skb_try_coalesce() to corrupt the page cache and gain root. Disclosed May 13, with public PoC and patch in v7.1-rc5.
deafnews.it
September 16, 2026 at 3:09 AM
Linux Detection Engineering for LPE: a layered Linux escalation framework pairs root-transition logic with rules for SUID abuse, unshare, Python exploits, and page-cache corruption, with Elastic Defend and Auditd coverage. #LinuxLPE #ElasticDefend
Linux Detection Engineering - Local Privilege Escalation
The article describes a layered Linux privilege escalation detection framework that combines general root-transition logic with technique-specific rules for SUID abuse, unshare, Python-driven exploits, and kernel page-cache corruption. It also reviews 2026 Linux LPE cases such as Copy Fail, DirtyFrag, Fragnesia, DirtyDecrypt, pedit COW, DirtyClone, CIFSwitch, OVSwrap, and CVE-2026-46333, showing how Elastic Defend and Auditd can catch them in practice. #CopyFail #DirtyFrag #Fragnesia #DirtyDecrypt #peditCOW #DirtyClone #CIFSwitch #OVSwrap #CVE-2026-46333
www.hendryadrian.com
September 13, 2026 at 10:45 PM
Three deterministic Linux kernel bugs turn any local shell into root - no race condition needed. https://intel.threadlinqs.com/threat/TL-2026-2424 #ThreatIntel #CVE_2026_31431 #CVE_2026_43284 #DirtyFrag
September 10, 2026 at 2:37 AM
tentang tiga kerentanan serius di Linux belakangan ini termasuk Copy Fail, Dirty Frag, dan Fragnesia beserta cara memperbaikinya.

#fediverse #mimpi #buruk #minggu

https://dalam.web.id/sistem-terbuka/tiga-bug-kritis-linux-lpe-dirty-frag
Mimpi Buruk Dua Minggu Terakhir Linux: 3 Bug Kritis Bersarang di Kernel
Sistem operasi Linux sedang diuji. Temukan analisis lengkap tiga celah Local Privilege Escalation mematikan dan mengapa update kernel saja tidak cukup tanpa reboot.
dalam.web.id
August 25, 2026 at 2:54 PM
🔥 New Kernel Vulnerabilities Discovered
Researchers have identified several kernel vulnerabilities, including Copy Fail, Dirty Frag, and Fragnesia, which could potentially compromise sys...

🌐 aitechcodex.uk/news/1655/?utm_source=bluesky&utm_medium=social&utm_campaign=daily_news 📡 t.me/AITechNewsUK
August 21, 2026 at 3:01 AM
> USN-8529-2: Linux kernel vulnerabilities
https://ubuntu.com/security/notices/USN-8529-2
USN-8529-2: Linux kernel vulnerabilities
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - InfiniBand drivers; - SCSI subsystem; - Thermal drivers; - USB over IP driver; - Network file system (NFS) server daemon; - SMB network file system; - Tracing infrastructure; - B.A.T.M.A.N. meshing protocol; - Ethernet bridge; - Ceph Core library; - DCCP (Datagram Congestion Control Protocol); - IPv4 networking; - IPv6 networking; - Netfilter; - RxRPC session sockets; - X.25 network layer; (CVE-2021-47202, CVE-2024-56643, CVE-2026-23272, CVE-2026-23455, CVE-2026-31402, CVE-2026-31607, CVE-2026-31637, CVE-2026-31659, CVE-2026-31682, CVE-2026-31685, CVE-2026-43011, CVE-2026-43037, CVE-2026-43038, CVE-2026-43383, CVE-2026-43407, CVE-2026-43414, CVE-2026-45988, CVE-2026-46043, CVE-2026-46119, CVE-2026-46243)
ubuntu.com
August 13, 2026 at 9:40 PM
> USN-8548-2: Linux kernel vulnerabilities
https://ubuntu.com/security/notices/USN-8548-2
USN-8548-2: Linux kernel vulnerabilities
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - SCSI subsystem; - Thermal drivers; - USB over IP driver; - File systems infrastructure; - Ext4 file system; - Network file system (NFS) server daemon; - SMB network file system; - Tracing infrastructure; - B.A.T.M.A.N. meshing protocol; - Ceph Core library; - DCCP (Datagram Congestion Control Protocol); - IPv4 networking; - IPv6 networking; - Netfilter; - RxRPC session sockets; - X.25 network layer; (CVE-2021-47117, CVE-2021-47202, CVE-2023-52646, CVE-2024-56643, CVE-2026-23455, CVE-2026-31402, CVE-2026-31607, CVE-2026-31637, CVE-2026-31659, CVE-2026-31685, CVE-2026-43011, CVE-2026-43037, CVE-2026-43038, CVE-2026-43383, CVE-2026-43407, CVE-2026-43414, CVE-2026-45988, CVE-2026-46119, CVE-2026-46243)
ubuntu.com
August 13, 2026 at 9:40 PM
> USN-8635-1: Linux kernel (Azure) vulnerabilities
https://ubuntu.com/security/notices/USN-8635-1
USN-8635-1: Linux kernel (Azure) vulnerabilities
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate attacker could use this issue to inject packets. (CVE-2025-27558) It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; - Cryptographic API; - GPU drivers; - InfiniBand drivers; - Media drivers; - NVIDIA Tegra memory controller driver; - Network drivers; - STMicroelectronics network drivers; - NVME drivers; - SCSI subsystem; - Thermal drivers; - USB over IP driver; - Ext4 file system; - Network file system (NFS) server daemon; - SMB network file system; - IPv4 networking; - Network traffic control; - TCP network protocol; - Tracing infrastructure; - Locking primitives; - B.A.T.M.A.N. meshing protocol; - Ethernet bridge; - Ceph Core library; - DCCP (Datagram Congestion Control Protocol); - IPv6 networking; - Multipath TCP; - Netfilter; - RxRPC session sockets; - SCTP protocol; - SMC sockets; - X.25 network layer; (CVE-2021-47202, CVE-2021-47354, CVE-2021-47378, CVE-2024-38612, CVE-2024-56643, CVE-2026-23272, CVE-2026-23455, CVE-2026-31402, CVE-2026-31405, CVE-2026-31414, CVE-2026-31448, CVE-2026-31607, CVE-2026-31637, CVE-2026-31649, CVE-2026-31657, CVE-2026-31659, CVE-2026-31668, CVE-2026-31682, CVE-2026-31685, CVE-2026-43011, CVE-2026-43037, CVE-2026-43038, CVE-2026-43198, CVE-2026-43383, CVE-2026-43407, CVE-2026-43414, CVE-2026-43493, CVE-2026-43499, CVE-2026-45988, CVE-2026-46043, CVE-2026-46119, CVE-2026-46243, CVE-2026-46266, CVE-2026-46331, CVE-2026-52924, CVE-2026-52931, CVE-2026-52955, CVE-2026-52982, CVE-2026-52986, CVE-2026-53002, CVE-2026-53006, CVE-2026-53045, CVE-2026-53088, CVE-2026-53176, CVE-2026-53225, CVE-2026-53228, CVE-2026-53359)
ubuntu.com
August 12, 2026 at 9:40 PM
NGINX Rift and Fragnesia: Two Critical Flaws at the Heart of Internet Infrastructure
NGINX Rift and Fragnesia: Two Critical Flaws at the Heart of Internet Infrastructure
An 18-year-old heap overflow hits nearly 19 million NGINX servers with unauthenticated RCE, while a local Linux exploit corrupts the page cache to gain root — both discovered with AI assistance, signaling a collapse in vulnerability incubation time.
deafnews.it
August 3, 2026 at 5:10 AM
Linux Fragnesia Local Privilege Escalation https://packetstorm.news/files/227346 #exploit
July 30, 2026 at 9:38 PM
Atualização crítica do kernel Linux para o #Ubuntu 20.04 e 18.04 LTS corrige vulnerabilidade Fragnesia com escalação de privilégios. Saiba como se proteger agora. -> tinyurl.com/27sdn3z5
O que é a USN-8615-2 e por que ele é tão importante?
Blog com notícias sobre, Linux, Android, Segurança , etc
tinyurl.com
July 30, 2026 at 2:13 PM
> USN-8615-2: Linux kernel (Raspberry Pi) vulnerabilities
https://ubuntu.com/security/notices/USN-8615-2
USN-8615-2: Linux kernel (Raspberry Pi) vulnerabilities
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - InfiniBand drivers; - STMicroelectronics network drivers; - NVME drivers; - SCSI subsystem; - USB over IP driver; - Network file system (NFS) server daemon; - SMB network file system; - Tracing infrastructure; - B.A.T.M.A.N. meshing protocol; - Ethernet bridge; - Ceph Core library; - IPv4 networking; - IPv6 networking; - Netfilter; - RxRPC session sockets; - X.25 network layer; (CVE-2026-23272, CVE-2026-23455, CVE-2026-31402, CVE-2026-31418, CVE-2026-31607, CVE-2026-31637, CVE-2026-31649, CVE-2026-31659, CVE-2026-31682, CVE-2026-31685, CVE-2026-43011, CVE-2026-43037, CVE-2026-43038, CVE-2026-43117, CVE-2026-43383, CVE-2026-43407, CVE-2026-43414, CVE-2026-45988, CVE-2026-46043, CVE-2026-46119, CVE-2026-46135, CVE-2026-46243)
ubuntu.com
July 29, 2026 at 9:40 AM
> USN-8615-1: Linux kernel vulnerabilities
https://ubuntu.com/security/notices/USN-8615-1
USN-8615-1: Linux kernel vulnerabilities
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - InfiniBand drivers; - STMicroelectronics network drivers; - NVME drivers; - SCSI subsystem; - USB over IP driver; - Network file system (NFS) server daemon; - SMB network file system; - Tracing infrastructure; - B.A.T.M.A.N. meshing protocol; - Ethernet bridge; - Ceph Core library; - IPv4 networking; - IPv6 networking; - Netfilter; - RxRPC session sockets; - X.25 network layer; (CVE-2026-23272, CVE-2026-23455, CVE-2026-31402, CVE-2026-31418, CVE-2026-31607, CVE-2026-31637, CVE-2026-31649, CVE-2026-31659, CVE-2026-31682, CVE-2026-31685, CVE-2026-43011, CVE-2026-43037, CVE-2026-43038, CVE-2026-43117, CVE-2026-43383, CVE-2026-43407, CVE-2026-43414, CVE-2026-45988, CVE-2026-46043, CVE-2026-46119, CVE-2026-46135, CVE-2026-46243)
ubuntu.com
July 28, 2026 at 3:40 PM
> USN-8548-1: Linux kernel vulnerabilities
https://ubuntu.com/security/notices/USN-8548-1
USN-8548-1: Linux kernel vulnerabilities
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - SCSI subsystem; - Thermal drivers; - USB over IP driver; - File systems infrastructure; - Ext4 file system; - Network file system (NFS) server daemon; - SMB network file system; - Tracing infrastructure; - B.A.T.M.A.N. meshing protocol; - Ceph Core library; - DCCP (Datagram Congestion Control Protocol); - IPv4 networking; - IPv6 networking; - Netfilter; - RxRPC session sockets; - X.25 network layer; (CVE-2021-47117, CVE-2021-47202, CVE-2023-52646, CVE-2024-56643, CVE-2026-23455, CVE-2026-31402, CVE-2026-31607, CVE-2026-31637, CVE-2026-31659, CVE-2026-31685, CVE-2026-43011, CVE-2026-43037, CVE-2026-43038, CVE-2026-43383, CVE-2026-43407, CVE-2026-43414, CVE-2026-45988, CVE-2026-46119, CVE-2026-46243)
ubuntu.com
July 15, 2026 at 3:40 PM
> USN-8529-1: Linux kernel vulnerabilities
https://ubuntu.com/security/notices/USN-8529-1
USN-8529-1: Linux kernel vulnerabilities
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - InfiniBand drivers; - SCSI subsystem; - Thermal drivers; - USB over IP driver; - Network file system (NFS) server daemon; - SMB network file system; - Tracing infrastructure; - B.A.T.M.A.N. meshing protocol; - Ethernet bridge; - Ceph Core library; - DCCP (Datagram Congestion Control Protocol); - IPv4 networking; - IPv6 networking; - Netfilter; - RxRPC session sockets; - X.25 network layer; (CVE-2021-47202, CVE-2024-56643, CVE-2026-23272, CVE-2026-23455, CVE-2026-31402, CVE-2026-31607, CVE-2026-31637, CVE-2026-31659, CVE-2026-31682, CVE-2026-31685, CVE-2026-43011, CVE-2026-43037, CVE-2026-43038, CVE-2026-43383, CVE-2026-43407, CVE-2026-43414, CVE-2026-45988, CVE-2026-46043, CVE-2026-46119, CVE-2026-46243)
ubuntu.com
July 10, 2026 at 3:40 PM