---
schema: 1
kind: vulnerability
title: "CVE-2026-46300 — Linux kernel: local privilege escalation via xfrm ESP-in-TCP (\"Fragnesia\"), PoC public"
headline: "CVE-2026-46300 — Linux kernel: local privilege escalation via xfrm ESP-in-TCP (\"Fragnesia\"), PoC public"
summary: "CVE-2026-46300 (\"Fragnesia\", CVSS 7.8) is a local privilege escalation vulnerability in the Linux kernel's xfrm ESP-in-TCP path, one of three CVEs Red Hat collectively groups as \"Dirty Frag\". Kubernetes-context proof-of-concept exploits are public, and Red Hat confirms RHEL kernels are affected (Wiz Research, 2026-05-13 · Red Hat RHSB-2026-003 · Aikido Security, 2026-09-04)."
discovered_at: "2026-05-15T05:00:07Z"
updated_at: "2026-09-05T05:10:00Z"
event_date: 2026-05-14
run_id: 2026-05-15-58b94fbd
priority: notable
immediate_action: null
tags:
  - vulnerabilities
  - lpe
  - poc-public
  - patch-available
regions:
  - global
sectors: []
techniques: [T1068, T1611]
entities:
  - "actor:uat-8616"
  - "trend:dirty-frag-linux-kernel-page-cache-lpe"
cves:
  - id: CVE-2026-46300
    cvss: "7.8"
    epss: "0.0948"
    type: lpe
    vector: local
    auth: post-auth
    status:
      - poc-public
      - patch-available
sources:
  - url: "https://www.wiz.io/blog/fragnesia-linux-kernel-local-privilege-escalation-via-esp-in-tcp"
    publisher: "Wiz Research, 2026-05-13"
    role: primary
  - url: "https://www.helpnetsecurity.com/2026/05/14/fragnesia-cve-2026-46300-linux-lpe-vulnerability/"
    publisher: "Help Net Security, 2026-05-14"
    role: corroborating
  - url: "https://access.redhat.com/security/vulnerabilities/RHSB-2026-003"
    publisher: "Red Hat (RHSB-2026-003)"
    date: "2026-07-03"
    role: primary
  - url: "https://cveawg.mitre.org/api/cve/CVE-2026-46300"
    publisher: "MITRE CVE Program (Linux kernel CNA)"
    date: "2026-09-01"
    role: primary
  - url: "https://www.aikido.dev/blog/dirty-frag"
    publisher: "Aikido Security"
    date: "2026-09-04"
    role: corroborating
  - url: "https://api.first.org/data/v1/epss?cve=CVE-2026-46300"
    publisher: "FIRST.org EPSS API"
    date: "2026-09-04"
    role: corroborating
  - url: "https://www.microsoft.com/en-us/security/blog/2026/05/08/active-attack-dirty-frag-linux-vulnerability-expands-post-compromise-risk/"
    publisher: "Microsoft Security Blog"
    date: "2026-05-08"
    role: corroborating
closed_sources: []
evidence:
  - quote: "net: skbuff: preserve shared-frag marker during coalescing"
    publisher: "MITRE CVE Program (Linux kernel CNA)"
    source_url: "https://cveawg.mitre.org/api/cve/CVE-2026-46300"
  - quote: "Three vulnerabilities, collectively known as \"Dirty Frag\", have been identified in networking subsystems of the Linux kernel, two of which affect Red Hat products."
    publisher: "Red Hat (RHSB-2026-003)"
    source_url: "https://access.redhat.com/security/vulnerabilities/RHSB-2026-003"
  - quote: "Red Hat says CVE-2026-43500 doesn't affect its products, while CVE-2026-43284 and CVE-2026-46300 do affect supported Red Hat Enterprise Linux kernels and anything built on them."
    publisher: "Aikido Security"
    source_url: "https://www.aikido.dev/blog/dirty-frag"
  - quote: "Researchers have already published working proof-of-concept exploits for Kubernetes, and Ubuntu spells out the risk of a container escape."
    publisher: "Aikido Security"
    source_url: "https://www.aikido.dev/blog/dirty-frag"
verification: multi-source
sourcing_note: >
  Red Hat's own bulletin (RHSB-2026-003) groups CVE-2026-46300 under the collective "Dirty Frag"
  name alongside CVE-2026-43284/CVE-2026-43500, labelling it specifically "Fragnesia (skb
  coalescing via ESP-in-TCP)" — confirming the ESP-in-TCP exploitation path this entry already
  described and the coalescing-marker root cause MITRE's own CNA record states are the same flaw,
  not competing accounts. EPSS (FIRST.org, 2026-09-04) is 0.0948 — an order of magnitude below
  the two co-disclosed CVE-2026-43284/CVE-2026-43500 scores (both above 0.92), consistent with
  no independently confirmed in-the-wild exploitation of CVE-2026-46300 itself as of 2026-09-05.
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: B
  credibility: 2
watchlist_hit: false
actions:
  - "**Apply Linux kernel security updates to patch CVE-2026-46300 \"Fragnesia\"** — Linux kernel LPE via xfrm ESP-in-TCP with a working public PoC; the vulnerability enables any local user to escalate to root. Critical for shared compute environments (VPS, container hosts, HPC clusters, university Linux systems). Apply the kernel update from your distribution and reboot; where immediate patching is not feasible, disable the `xfrm_espintcp` module and restrict `CAP_NET_ADMIN` capability."
updates:
  - at: "2026-09-05T05:10:00Z"
    run_id: 2026-09-05T0409Z-intel
    type: update
    summary: >
      CVE-2026-46300's CVSS score has now been published (7.8) and Red Hat's own bulletin
      confirms RHEL kernels are affected (unlike sibling CVE-2026-43500, which Red Hat states
      does not affect its products). Public proof-of-concept exploits now target Kubernetes
      specifically, and Red Hat's bulletin groups this CVE under the collective "Dirty Frag" name
      alongside CVE-2026-43284/CVE-2026-43500, confirming the ESP-in-TCP exploitation path this
      entry already described and the coalescing-marker root cause are the same flaw.
    fields: [updated_at, cves, summary, sources, evidence, entities, techniques, classification, sourcing_note, body]
migrated_from: briefs/2026-05-15.md
---

CVE-2026-46300 (codename "Fragnesia") is a local privilege escalation vulnerability in the Linux kernel's `xfrm` IPsec subsystem, specifically in the ESP-over-TCP code path that provides NAT traversal fallback for IPsec connections ([Wiz Research, 2026-05-13](https://www.wiz.io/blog/fragnesia-linux-kernel-local-privilege-escalation-via-esp-in-tcp) · [Help Net Security, 2026-05-14](https://www.helpnetsecurity.com/2026/05/14/fragnesia-cve-2026-46300-linux-lpe-vulnerability/)). The vulnerability was discovered by William Bowling of Zellic.io using Zellic's AI-agentic source code auditing tool; Wiz Research (whose researcher Hyunwoo Kim had previously discovered the related Dirty Frag vulnerability family) published the technical writeup. A working proof-of-concept demonstrating escalation from an unprivileged local user to root on unpatched kernels has been released (hosted at `github.com/v12-security/pocs`). Exploitation requires local code execution on the target — there is no known remote exploitation path absent a prior foothold or a co-chained remote vulnerability (e.g., an RCE that drops a low-privilege shell). Fragnesia is therefore primarily relevant as a post-compromise privilege-escalation primitive and as a jailbreak-class risk in shared compute environments: VPS and bare-metal hosting providers, university Linux clusters, multi-tenant cloud workloads running on shared kernels, and container environments where the kernel namespace boundary can be crossed. MITRE ATT&CK: T1068 (Exploitation for Privilege Escalation). No in-the-wild exploitation reported as of 2026-05-15. Affected: Linux kernels shipping the xfrm ESP-in-TCP implementation across the 5.x and 6.x LTS series — consult your distribution's security bulletin for the exact affected package version range. Distributions shipping patches as of 2026-05-15 include upstream Linux and major vendors (Ubuntu, Debian, RHEL, SUSE); apply the available kernel update and reboot. Interim workaround: disable the `xfrm_espintcp` kernel module where IPsec ESP-over-TCP is not operationally required (`modprobe -r esp6_offload esp4_offload` where applicable); also consider restricting `CAP_NET_ADMIN` capability to reduce the xfrm attack surface in multi-tenant environments.


#### CVE Summary Table

| CVE | Product | CVSS | EPSS | KEV | Exploited | Patch | Source |
|---|---|---|---|---|---|---|---|
| CVE-2026-20182 | Cisco Catalyst SD-WAN Controller / Manager | 10.0 (v3.1) | n/a | Yes (2026-05-14) | Yes — UAT-8616 + 10+ clusters | 20.9.9.1 / 20.12.7.1 / 20.15.5.2 | [Cisco PSIRT](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW) |
| CVE-2026-42945 | NGINX Open Source 0.6.27–1.30.0; NGINX Plus R32–R36; NGINX Ingress Controller, Gateway Fabric, F5 WAF/App Protect | 9.2 (v4.0) / 8.1 (v3.1) | n/a | No | No (PoC public) | NGINX OS 1.30.1 / Plus R36 P4 | [depthfirst / NCSC-CH](https://depthfirst.com/research/nginx-rift-achieving-nginx-rce-via-an-18-year-old-vulnerability) |
| CVE-2026-46300 | Linux kernel xfrm ESP-in-TCP subsystem ("Fragnesia") — LPE, local only | 7.8 (v3.1) | n/a | No | No confirmed ITW (Kubernetes PoC public) | Distro kernel updates (2026-05-13+) | [Wiz Research](https://www.wiz.io/blog/fragnesia-linux-kernel-local-privilege-escalation-via-esp-in-tcp) |
| CVE-2026-45793 | PHP Composer (1.x, 2.x) — GitHub Actions token disclosure in error output | n/a | n/a | No | No | Composer 2.9.8 / 2.2.28 / 1.10.28 | [Packagist blog](https://blog.packagist.com/composer-2-9-8-and-2-2-28-fix-github-actions-token-disclosure-in-error-messages/) |

## Update — 2026-09-05T05:10:00Z

CVE-2026-46300 now carries a published score, CVSS 7.8 ([MITRE CVE Program, 2026-09-01](https://cveawg.mitre.org/api/cve/CVE-2026-46300)), and Red Hat's own security bulletin groups it under the collective "Dirty Frag" name alongside CVE-2026-43284 and CVE-2026-43500, labelling it specifically "Fragnesia (skb coalescing via ESP-in-TCP)": "three vulnerabilities, collectively known as 'Dirty Frag', have been identified in networking subsystems of the Linux kernel, two of which affect Red Hat products" ([Red Hat RHSB-2026-003](https://access.redhat.com/security/vulnerabilities/RHSB-2026-003)). Applicability splits per CVE: "Red Hat says CVE-2026-43500 doesn't affect its products, while CVE-2026-43284 and CVE-2026-46300 do affect supported Red Hat Enterprise Linux kernels and anything built on them" ([Aikido Security, 2026-09-04](https://www.aikido.dev/blog/dirty-frag)) — any RHEL, OpenShift or RHEL CoreOS estate must confirm the CVE-2026-46300 fix specifically, not only the earlier two. Exploitation now extends to a container-relevant proof-of-concept: "researchers have already published working proof-of-concept exploits for Kubernetes, and Ubuntu spells out the risk of a container escape" ([Aikido Security, 2026-09-04](https://www.aikido.dev/blog/dirty-frag)) — because containers share the host kernel, a compromised workload that can reach the vulnerable code path (governed by seccomp, pod security policy and user-namespace settings) can escalate to root on the node. No source states confirmed in-the-wild exploitation of this specific CVE; Microsoft's previously reported limited in-the-wild activity ("privilege escalation involving 'su'") was itself stated as ambiguous between the "Dirty Frag" family and the separate, earlier "Copy Fail" vulnerability (CVE-2026-31431) from process logs alone ([Microsoft Security Blog, 2026-05-08](https://www.microsoft.com/en-us/security/blog/2026/05/08/active-attack-dirty-frag-linux-vulnerability-expands-post-compromise-risk/)) — not a distinction between the two Dirty Frag CVEs themselves, and not specific evidence of exploitation for CVE-2026-46300.

**Detection:** exposure check — compare `uname -r` against the distribution vendor's fixed package version, not the upstream kernel version string, since backports mean a patched RHEL/Ubuntu host can report an old-looking version. `lsmod | grep -E 'esp4|esp6'` confirms whether IPsec is in active use on the host. In container/Kubernetes environments, review seccomp profile enforcement, pod security policy restrictions and unprivileged user-namespace availability as the factors governing whether a compromised workload can actually reach this kernel path.
