Back Cybernews Patching one Linux kernel critical exploit spawns another: a third vulnerability in two weeks
A fix for the Linux kernel critical exploit has seemingly introduced another critical local privilege escalation exploit, a third in two weeks. Security professionals are now frustrated with disclosures dropping without any embargoes for defenders to prepare.
A Pandora’s box of Linux kernel vulnerabilities has been opened.
Every Linux kernel since 2017 is vulnerable to a local privilege escalation exploit, as demonstrated by the first vulnerability, dubbed Copy Fail , two weeks ago.
As kernel maintainers and major Linux distributions scrambled to patch it, another major exploit dropped, named “Dirty Frag,” achieving the same result as exploiting other kernel vulnerabilities.
It now appears that the mainline kernel patch has introduced another vulnerability.
William Bowling, a security researcher, and the V12 security team dropped a universal local privilege escalation vulnerability, called Fragnesia , on GitHub.
It is a new variant of the Dirty Frag vulnerability and, similarly, exploits the XFRM ESP-in-TCP subsystem to achieve a kernel memory-write primitive, the Microsoft Threat Intelligence team explained.
All the vulnerabilities corrupt the page cache memory of system executables like usr/bin/su, tricking the kernel into running attacker-injected code when they are executed the time. Ultimately, it opens a shell with root privileges.
Hyunwoo Kim, a security researcher who discovered and reported the original Dirty Frag vulnerability, analyzed the new exploit and said that the patch, which fixed Dirty Frag, accidentally activated the code path for Fragnesia, which was previously dormant.
“This vulnerability is a path that was accidentally activated after the introduction of f4c50a4034e6 (2026-05-05), the patch for CVE-2026-43284 in the Dirty Frag chain. In other words, the effective vulnerability window is from f4c50a4034e6 (2026-05-05) to upstream – approximately 9 days,” the security researcher said in an email to the Openwall Open Source Security mailing list.
Kim recommends keeping the Dirty Frag mitigations in place, while the patch for Fragnesia is underway.
The researcher also notes that the new flaw requires the attacker to have permission to create user namespaces. This means that some distributions that restrict unprivileged user namespaces with AppArmor, such as Ubuntu, would block the exploit. However, attackers can still make it work by chaining Fragnesia with other separate vulnerabilities.
Some security professionals are now calling out researchers publicly releasing exploits while they’re “hot.”
“Am I correct in my understanding that this ‘disclosure’ was done solely by dropping the code on GitHub, with no advance notification to the Linux kernel or distros? Does that seem reasonable because it's adjacent to the vulnerability whose coattails it rides?” Jan Schaumann, a Chief Information Security Architect at Akamai, and an Adjunct Professor of Computer Science at Stevens Institute of Technology, criticized how the disclosure was handled.
The expert acknowledges that the realistic utility of embargoes is shrinking dramatically.
“But this ‘drop it while it's hot’ approach to seemingly promote yet another AI vulnerability discovery service is a trend I can't abide.”
If patching for Fragnesia is not yet possible, Microsoft recommends assessing whether esp4, esp6, and related xfrm/IPsec kernel functionality can be temporarily disabled safely, restricting unnecessary local shell access, hardening containerized workloads, and monitoring for abnormal activity.
Unlock more exclusive Cybernews content on YouTube.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
