Linux Fragnesia Flaw Spawns Root Exploits
Linux kernels just got hit with Fragnesia, another local root bug in the IPsec code. Unprivileged users splice file data into sockets then trigger bad decryption to corrupt page cache on su.
CVE-2026-46300 scores CVSS 7.8. Attackers build keystream tables via AF_ALG, flip bytes in read-only pages like /usr/bin/su for instant root. Public PoC available from V12 Security.
Hits all major distros on kernels before May 13 patches from Ubuntu, RHEL, AlmaLinux. Works inside containers or CI if AppArmor allows unprivileged namespaces.
Third kernel root bug in two weeks after Copy Fail and Dirty Frag.
