All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

Fragnesia: New Linux Kernel Local Privilege Escalation Vulnerability Disclosed

By

mikece

18d ago· 1 min readenNews

Summary

A new Linux kernel local privilege escalation (LPE) vulnerability called "Fragnesia" has been made public, following closely on the heels of the similar "Dirty Frag" vulnerability. Fragnesia is a separate bug within the ESP/XFRM code that contains a logic bug allowing arbitrary byte writes into the kernel page cache of read-only files. The vulnerability was announced by V12 Security on the open-source security mailing list.

Key quotes

· 2 pulled
Announced today on the open-source security mailing list by V12 Security is Fragnesia as a local privilege escalation exploit that is of the same vulnerability class as Dirty Frag.
Fragnesia centers around a separate bug within the ESP/XFRM code with a logic bug to allow arbitrary byte writes into the kernel page cache of read-only files.
Snippet from the RSS feed
Following last week's disclosure of the Dirty Frag vulnerability for the Linux kernel, which only finished being patched up in mainline on Monday, Fragnesia is now public as a similar local privilege escalation (LPE) vulnerability.

You might also wanna read