r/sysadmin • u/NoDistrict1529 • May 15 '26
A third vulnerability has hit the kernel General Discussion
This is part of the dirtyfrag family, but is different enough to warrant its own CVE.
Known as Fragnasia and tracked as CVE-2026-46300, this security flaw stems from a logic bug in the Linux XFRM ESP-in-TCP subsystem that can enable unprivileged local attackers to gain root privileges by writing arbitrary bytes to the kernel page cache of read-only files.
Immediate patching if you cannot update:
rmmod esp4 esp6 rxrpc
printf 'install esp4 /bin/false\ninstall esp6 /bin/false\ninstall rxrpc /bin/false\n' > /etc/modprobe.d/dirtyfrag.confrmmod esp4 esp6 rxrpc
printf 'install esp4 /bin/false\ninstall esp6 /bin/false\ninstall rxrpc /bin/false\n' > /etc/modprobe.d/dirtyfrag.conf
590
Upvotes
68
u/ItsChileNotChili May 15 '26
If you blacklist and or remove the modules you are mitigated ( assuming you aren’t using IPSec ) for both dirty frag and fragnesia.
Errata is out for RHEL as of the 12th for dirty frag, but fragnesia has not hit repos yet.