Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Linux Kernel Flaw Grants Root Access Easily

Critical Linux Kernel Flaw Grants Root Access Easily

Posted on May 13, 2026 By CWS

A newly identified vulnerability in the Linux kernel, named Fragnesia, allows local users without privileges to gain root access, posing a significant threat to system security. This flaw is notable for not requiring a race condition, enhancing its reliability compared to similar exploits.

Discovery and Nature of Fragnesia

Fragnesia was discovered by William Bowling of the V12 security team. It is part of a growing category of serious kernel vulnerabilities that challenge existing Linux security protocols. This particular bug is part of the Dirty Frag class, related to the well-known Dirty Pipe and Copy Fail bugs, but it targets a different logic flaw in the Linux XFRM ESP-in-TCP subsystem.

The vulnerability exploits a kernel error where it fails to recognize shared fragments during the coalescing of socket buffers, inadvertently corrupting memory it should not access.

Mechanism of the Exploit

Fragnesia leverages a logic flaw in the handling of ESP-in-TCP ULP mode by the kernel. When a TCP socket shifts to espintcp ULP after data is already queued, the kernel erroneously processes the pages as ESP ciphertext. This results in an AES-GCM keystream byte being XORed into a read-only file’s kernel page cache without needing a race condition.

The exploit is executed by constructing a 256-entry lookup table of possible keystream bytes, allowing an attacker to alter any byte in a cached file by selecting the right nonce. This method enables the overwriting of the first 192 bytes of /usr/bin/su with a malicious ELF stub that elevates privileges and opens a root shell.

Impact and Mitigation Strategies

All Linux kernels affected by Dirtyfrag are susceptible, specifically those before May 13, 2026. While a patch has been submitted, systems remain at risk until it is applied. Administrators should immediately remove the vulnerable ESP modules using:

  • rmmod esp4 esp6 rxrpc
  • printf ‘install esp4 /bin/falseninstall esp6 /bin/falseninstall rxrpc /bin/false’ > /etc/modprobe.d/dirtyfrag.conf

It’s crucial to flush the page cache to prevent persistence of the exploit, using echo 1 | tee /proc/sys/vm/drop_caches or rebooting the system. A proof-of-concept is publicly available on GitHub, emphasizing the urgency for immediate action by organizations to patch affected systems.

Stay updated on this and other security issues by following us on platforms like Google News, LinkedIn, and X.

Cyber Security News Tags:Cybersecurity, Dirty Frag, ESP modules, ESP-in-TCP, Exploit, GitHub, Kernel, Linux, Linux servers, proof-of-concept, root access, security patch, system administrators, Vulnerability, William Bowling

Post navigation

Previous Post: Explore ROI for Cyber-Physical Security in Live Webinar
Next Post: Microsoft’s AI MDASH System Detects 16 Windows Vulnerabilities

Related Posts

New EDR-Freeze Tool That Puts EDRs And Antivirus Into A Coma State New EDR-Freeze Tool That Puts EDRs And Antivirus Into A Coma State Cyber Security News
Hugging Face Exploited in North Korean Malware Attack Hugging Face Exploited in North Korean Malware Attack Cyber Security News
Thousands of Rockwell PLCs Put Water Systems at Risk Thousands of Rockwell PLCs Put Water Systems at Risk Cyber Security News
New Study Shows GPT-5.2 Can Reliably Develop Zero-Day Exploits at Scale New Study Shows GPT-5.2 Can Reliably Develop Zero-Day Exploits at Scale Cyber Security News
Threat Actors Embed Malicious RMM Tools to Gain Silent Initial Access to Organizations Threat Actors Embed Malicious RMM Tools to Gain Silent Initial Access to Organizations Cyber Security News
Malware Disguised as Teams and Zoom Apps Targets Enterprises Malware Disguised as Teams and Zoom Apps Targets Enterprises Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Gunra Ransomware Targets Global Infrastructure via Exploited Flaws
  • Zenity Secures $125M to Boost AI Security Governance
  • Zoom Annotation Flaw Risks Meeting Participant Security
  • Intel’s $20B Stock Sale Boosts Chip Supply Chain Security
  • Kimwolf v7 Botnet Mimics Legitimate Traffic with HTTP/2

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Gunra Ransomware Targets Global Infrastructure via Exploited Flaws
  • Zenity Secures $125M to Boost AI Security Governance
  • Zoom Annotation Flaw Risks Meeting Participant Security
  • Intel’s $20B Stock Sale Boosts Chip Supply Chain Security
  • Kimwolf v7 Botnet Mimics Legitimate Traffic with HTTP/2

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark