Fragnesia Linux Kernel Local Root via ESP-TCP
Linux kernel scores another page-cache LPE in the Dirty Frag family. Unprivileged locals grab root through ESP-in-TCP mishandling.
Fragnesia exploits logic flaws in XFRM ESP-in-TCP during skb coalescing. Attackers splice tainted frags into TCP queues, then AES-GCM decrypts corrupt page cache on setuid binaries like su. No CVE yet, public PoC overwrites su with ELF shellcode.
Hits systems loading esp4, esp6, or rxrpc modules across Ubuntu, RHEL, Fedora, Debian. Needs user namespaces for CAP_NET_ADMIN but no host privileges.
Corruption stays in page cache, leaves on-disk binary untouched.
