Fragnesia CVE-2026-46300: Linux Kernel LPE Vulnerability Explained

Umut Bayram | 5 MIN READ

| May 21, 2026

Key Takeaways

  • Fragnesia (CVE-2026-46300) is a high-severity Linux kernel LPE vulnerability (CVSS 7.8) affecting the XFRM ESP-in-TCP subsystem, and it works across nearly all Linux distributions.
  • The root cause is a logic flaw where the socket buffer fails to recognize shared fragment pages during memory coalescing, causing the kernel to perform in-place AES-GCM decryption directly on file page cache entries.
  • The exploit allows local unprivileged attackers to write arbitrary bytes into the page cache of read-only files without any race conditions, making it highly reliable.
  • By repeatedly triggering the flaw, an attacker can write a 192-byte ELF stub into the page cache of a setuid-root binary (such as /usr/bin/su) and spawn a root shell, while leaving the original on-disk file untouched.
  • Picus Threat Library includes dedicated threats for simulating Fragnesia vulnerability attacks, enabling security teams to validate their defenses against this vulnerability.

Fragnesia (CVE-2026-46300), disclosed on May 13, 2026, is a high-severity Linux Kernel bug that gives the attacker a reliable way to escalate privileges locally. Using the memory coalescing bug in the XFRM ESP-in-TCP module, an adversary is able to overwrite a read-only file in the page cache, thereby spawning a root shell.

In this blog post, we break down what Fragnesia is, how it works under the hood, how it differs from the related Dirty Frag vulnerability family, and what steps you can take to remediate or mitigate the risk in your environment.

What Is Fragnesia Vulnerability?

Fragnesia (CVE-2026-46300) is a universal (works for nearly all Linux distros) LPE vulnerability found in the XFRM ESP-in-TCP subsystem of the Linux kernel. It is a high-severity vulnerability (CVSS 7.8) [1].

The vulnerability belongs to the "Dirty Frag" class of vulnerabilities, but it is a different logic bug. Exploiting the vulnerability allows local unprivileged attackers to write arbitrary bytes into the page cache of read-only files in the kernel without requiring any race conditions. As a result, an attacker can overwrite executable files in memory, effectively achieving a root compromise.

What Is the Root Cause of Fragnesia Vulnerability?

The underlying problem associated with the Fragnesia flaw (CVE-2026-46300) lies in a particular logic flaw in the Linux kernel's XFRM ESP-in-TCP subsystem. The problem arises since the socket buffer (skb) basically forgets about the shared nature of the fragment during memory coalescing. The bug is related to the family of page-cache write bugs, including such known as the Dirty Pipe vulnerability.

This particular flaw can be exploited when transitioning the TCP socket to espintcp ULP (Upper Layer Protocol) after splicing data from the file to the receive queue. Instead of treating the spliced data in a safe way, the kernel processes queued file pages as encrypted ESP ciphertext. Thus, in-place decryption is executed on the file page cache, where the AES-GCM keystream byte (at the counter block position 2, byte 0) is XOR-ed with the data. An attacker may manipulate the contents of a read-only file by selecting a desired keystream byte via controlling IV nonce.

How Fragnesia Exploit Works?

To achieve its goal, the Fragnesia exploit exploits the kernel's page cache to drop the malicious payload in the targeted executable.

Initially, the adversary creates two separate namespaces for userspace and the network, where they can get CAP_NET_ADMIN capability. Then, the adversary installs a transport-mode ESP-in-TCP security association using AES-128-GCM and a hard-coded key within the namespace.

Subsequently, the Fragnesia exploit pre-computes a lookup table mapping each potential keystream byte to the appropriate IV nonce. Then the exploit uses a splice-and-ULP trigger, which means that the attacker splices data (e.g., from /usr/bin/su) to the TCP stream while preventing the receiver from installing ULP until all data has been enqueued in the TCP buffer.

Upon installing the ULP, the kernel will erroneously execute an in-place decryption process by XORing the precisely chosen keystream byte with the target file's page cache.

Repeating the trigger causes controlled modifications of the contents of the file in the page cache. As soon as a 192-byte ELF stub is written to the page cache of the targeted binary, the exploit executes it and spawns a root shell.

What Is the Impact of Fragnesia Vulnerability?

Fragnesia enables an attacker to gain root access from a local unprivileged user account. Through writing arbitrary contents in the page caches of system executables (such as /usr/bin/su), the attacker would be able to execute arbitrary code using the privileges of the setuid-root system binaries.

A notable feature of this exploitation is its reliability due to the absence of race conditions involved. In addition, since all modifications take place in the page caches within the kernel, the original on-disk executable is left untouched.

What Is the Difference Between Fragnesia and Dirty Frag?

Though both Fragnesia and Dirty Frag vulnerabilities fall under the Dirty Frag family, they affect different systems, as well as operate based on different root causes.

Dirty Frag exploits two vulnerabilities, CVE-2026-43284 and CVE-2026-43500, in order to exploit the IPsec ESP protocol and RxRPC protocol, enabling the system to bypass Copy-on-Write protections.

Conversely, Fragnesia, which is known as CVE-2026-46300, is a separate vulnerability affecting the XFRM ESP-in-TCP subsystem. The problem behind this vulnerability arises from the fact that a socket buffer does not remember a fragmented piece in the coalesced memory operation.

How To Remediate Fragnesia Vulnerability?

To eliminate the vulnerability, update your Linux distribution to the version containing the kernel patch released on May 13, 2026.

If this is not possible, for mitigation purposes, you can disable the vulnerable modules as a temporary measure:

rmmod esp4 esp6 rxrpc
printf 'install esp4 /bin/false\ninstall esp6 /bin/false\ninstall rxrpc /bin/false\n' > /etc/modprobe.d/dirtyfrag.conf

How Picus Simulates Fragnesia Vulnerability Attacks?

We also strongly suggest simulating Fragnesia vulnerability attacks to test the effectiveness of your security controls against real-life cyber attacks using the Picus Security Validation Platform. You can also test your defenses against other vulnerability exploitation attacks, such as regreSSHion, Citrix Bleed, and Follina, within minutes with a 14-day free trial of the Picus Platform.

Picus Threat Library includes the following threats for the Fragnesia vulnerability attacks:

Threat ID

Threat Name

Attack Module

52307

Linux Kernel Fragnesia Elevation of Privilege Vulnerability Threat

Network Infiltration

49944

Linux Kernel Fragnesia Elevation of Privilege Vulnerability Threat

E-mail Infiltration

Start simulating emerging threats today and get actionable mitigation insights with a 14-day free trial of the Picus Security Validation Platform.

References

[1] “pocs/fragnesia/README.md at main · v12-security/pocs,” GitHub. Accessed: May 19, 2026. [Online]. Available: https://github.com/v12-security/pocs/blob/main/fragnesia/README.md

 
Fragnesia (CVE-2026-46300) is a high-severity Linux kernel local privilege escalation (LPE) vulnerability with a CVSS score of 7.8. It affects the XFRM ESP-in-TCP subsystem and works across nearly all Linux distributions. It allows local unprivileged attackers to write arbitrary bytes into the page cache of read-only files without requiring any race conditions.
The root cause is a logic flaw in the Linux kernel's XFRM ESP-in-TCP subsystem. The socket buffer fails to recognize the shared nature of a fragment during memory coalescing. This causes the kernel to treat spliced file pages as encrypted ESP ciphertext and perform in-place AES-GCM decryption directly on file page cache entries, allowing an attacker to manipulate read-only file contents.
The attacker creates separate user and network namespaces to obtain CAP_NET_ADMIN capability, then installs a transport-mode ESP-in-TCP security association using AES-128-GCM. By splicing data from a target binary and triggering ULP installation, the kernel performs in-place decryption on the file's page cache. Repeating this process writes a 192-byte ELF stub into the targeted binary's page cache, spawning a root shell.
Both belong to the Dirty Frag vulnerability family but involve different root causes and subsystems. Dirty Frag chains two vulnerabilities (CVE-2026-43284 and CVE-2026-43500) affecting the IPsec ESP and RxRPC protocols to bypass Copy-on-Write protections. Fragnesia (CVE-2026-46300) is a separate flaw in the XFRM ESP-in-TCP subsystem where the socket buffer fails to track fragment sharing during memory coalescing.
Fragnesia enables a local unprivileged attacker to gain full root access by writing arbitrary content into the page cache of system executables such as /usr/bin/su. Because all modifications occur in kernel page cache, the original on-disk file remains untouched. The exploit is highly reliable due to the complete absence of race conditions.
The primary remediation is updating your Linux distribution to the version containing the kernel patch released on May 13, 2026. If patching is not immediately possible, a temporary mitigation is to disable the vulnerable kernel modules by running the appropriate rmmod commands for esp4, esp6, and rxrpc, and adding corresponding install restrictions to the modprobe configuration file.
Picus Threat Library includes dedicated threats for simulating Fragnesia vulnerability attacks across two attack modules: Network Infiltration (Threat ID 52307) and E-mail Infiltration (Threat ID 49944). Using the Picus Security Validation Platform, security teams can simulate Fragnesia attacks and receive actionable mitigation insights to validate and strengthen their defenses.

Table of Contents

Ready to start? Request a demo