<Vulnerability name="CVE-2026-46300">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-05-13T12:00:00</PublicDate>
    <Bugzilla id="2477015" url="https://bugzilla.redhat.com/show_bug.cgi?id=2477015" xml:lang="en:us">
kernel: "Fragnesia" is a variant of Dirty Frag vulnerability in the ESP/XFRM leading to Local Privilege Escalation (LPE) vulnerability in the Linux kernel
    </Bugzilla>
    <CVSS3 status="verified">
        <CVSS3BaseScore>7.8</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-123</CWE>
    <Details xml:lang="en:us" source="Mitre">
In the Linux kernel, the following vulnerability has been resolved:

net: skbuff: preserve shared-frag marker during coalescing

skb_try_coalesce() can attach paged frags from @from to @to.  If @from
has SKBFL_SHARED_FRAG set, the resulting @to skb can contain the same
externally-owned or page-cache-backed frags, but the shared-frag marker
is currently lost.

That breaks the invariant relied on by later in-place writers.  In
particular, ESP input checks skb_has_shared_frag() before deciding
whether an uncloned nonlinear skb can skip skb_cow_data().  If TCP
receive coalescing has moved shared frags into an unmarked skb, ESP can
see skb_has_shared_frag() as false and decrypt in place over page-cache
backed frags.

Propagate SKBFL_SHARED_FRAG when skb_try_coalesce() transfers paged
frags.  The tailroom copy path does not need the marker because it copies
bytes into @to's linear data rather than transferring frag descriptors.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in the Linux kernel's XFRM ESP-in-TCP subsystem. Unsafe in-place cryptographic processing allows a low-privileged local attacker to write arbitrary bytes into the page cache of read-only files, including sensitive system files. An attacker can exploit this to overwrite privileged binaries and gain root privileges.
    </Details>
    <Statement xml:lang="en:us">
This issue is classified as Important, rather than Critical severity, because exploitation requires local access to the system. A low-privileged local attacker can exploit this flaw in the Linux kernel's XFRM ESP-in-TCP subsystem to gain root privileges by overwriting sensitive system files. Exploitation does not require user interaction, potentially resulting in full compromise of confidentiality, integrity, and availability.
    </Statement>
    <Mitigation xml:lang="en:us">
See the security bulletin for a detailed mitigation procedure.
    </Mitigation>
    <AffectedRelease cpe="cpe:/a:redhat:enterprise_linux_nvidia:10::el10">
        <ProductName>NVIDIA for RHEL 10</ProductName>
        <ReleaseDate>2026-05-20T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:19540">RHSA-2026:19540</Advisory>
        <Package name="kernel">kernel-0:6.12.0-211.8.el10nv</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:enterprise_linux:10.2">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <ReleaseDate>2026-05-20T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:19569">RHSA-2026:19569</Advisory>
        <Package name="kernel">kernel-0:6.12.0-211.16.1.el10_2</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:enterprise_linux_eus:10.0">
        <ProductName>Red Hat Enterprise Linux 10.0 Extended Update Support</ProductName>
        <ReleaseDate>2026-05-21T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:20299">RHSA-2026:20299</Advisory>
        <Package name="kernel">kernel-0:6.12.0-55.75.1.el10_0</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:enterprise_linux:8::nfv">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <ReleaseDate>2026-05-20T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:19664">RHSA-2026:19664</Advisory>
        <Package name="kernel-rt">kernel-rt-0:4.18.0-553.125.1.rt7.466.el8_10</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:enterprise_linux:8">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <ReleaseDate>2026-05-20T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:19666">RHSA-2026:19666</Advisory>
        <Package name="kernel">kernel-0:4.18.0-553.125.1.el8_10</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:rhel_aus:8.4">
        <ProductName>Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support</ProductName>
        <ReleaseDate>2026-05-21T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:20130">RHSA-2026:20130</Advisory>
        <Package name="kernel">kernel-0:4.18.0-305.192.1.el8_4</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:rhel_eus_long_life:8.4">
        <ProductName>Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On</ProductName>
        <ReleaseDate>2026-05-21T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:20130">RHSA-2026:20130</Advisory>
        <Package name="kernel">kernel-0:4.18.0-305.192.1.el8_4</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:rhel_aus:8.6">
        <ProductName>Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support</ProductName>
        <ReleaseDate>2026-05-21T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:20051">RHSA-2026:20051</Advisory>
        <Package name="kernel">kernel-0:4.18.0-372.193.1.el8_6</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:rhel_tus:8.6">
        <ProductName>Red Hat Enterprise Linux 8.6 Telecommunications Update Service</ProductName>
        <ReleaseDate>2026-05-21T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:20051">RHSA-2026:20051</Advisory>
        <Package name="kernel">kernel-0:4.18.0-372.193.1.el8_6</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:rhel_e4s:8.6">
        <ProductName>Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions</ProductName>
        <ReleaseDate>2026-05-21T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:20051">RHSA-2026:20051</Advisory>
        <Package name="kernel">kernel-0:4.18.0-372.193.1.el8_6</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:rhel_tus:8.8">
        <ProductName>Red Hat Enterprise Linux 8.8 Telecommunications Update Service</ProductName>
        <ReleaseDate>2026-05-20T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:19521">RHSA-2026:19521</Advisory>
        <Package name="kernel">kernel-0:4.18.0-477.143.1.el8_8</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:rhel_e4s:8.8">
        <ProductName>Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions</ProductName>
        <ReleaseDate>2026-05-20T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:19521">RHSA-2026:19521</Advisory>
        <Package name="kernel">kernel-0:4.18.0-477.143.1.el8_8</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <ReleaseDate>2026-05-20T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:19568">RHSA-2026:19568</Advisory>
        <Package name="kernel">kernel-0:5.14.0-687.10.1.el9_8</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <ReleaseDate>2026-05-20T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:19568">RHSA-2026:19568</Advisory>
        <Package name="kernel">kernel-0:5.14.0-687.10.1.el9_8</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_e4s:9.0">
        <ProductName>Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions</ProductName>
        <ReleaseDate>2026-05-20T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:19705">RHSA-2026:19705</Advisory>
        <Package name="kernel">kernel-0:5.14.0-70.180.1.el9_0</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_e4s:9.0::nfv">
        <ProductName>Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions</ProductName>
        <ReleaseDate>2026-05-20T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:19711">RHSA-2026:19711</Advisory>
        <Package name="kernel-rt">kernel-rt-0:5.14.0-70.180.1.rt21.252.el9_0</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_e4s:9.2">
        <ProductName>Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions</ProductName>
        <ReleaseDate>2026-05-26T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:20593">RHSA-2026:20593</Advisory>
        <Package name="kernel">kernel-0:5.14.0-284.172.1.el9_2</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_e4s:9.2::nfv">
        <ProductName>Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions</ProductName>
        <ReleaseDate>2026-05-20T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:19875">RHSA-2026:19875</Advisory>
        <Package name="kernel-rt">kernel-rt-0:5.14.0-284.172.1.rt14.457.el9_2</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_eus:9.4">
        <ProductName>Red Hat Enterprise Linux 9.4 Extended Update Support</ProductName>
        <ReleaseDate>2026-05-21T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:20054">RHSA-2026:20054</Advisory>
        <Package name="kernel">kernel-0:5.14.0-427.126.1.el9_4</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_eus:9.6">
        <ProductName>Red Hat Enterprise Linux 9.6 Extended Update Support</ProductName>
        <ReleaseDate>2026-05-21T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:20129">RHSA-2026:20129</Advisory>
        <Package name="kernel">kernel-0:5.14.0-570.116.1.el9_6</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:openshift:4.16::el9">
        <ProductName>Red Hat OpenShift Container Platform 4.16</ProductName>
        <ReleaseDate>2026-05-29T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:20087">RHSA-2026:20087</Advisory>
        <Package name="rhcos">rhcos-416.94.202605200242-0</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:openshift:4.21::el8">
        <ProductName>Red Hat OpenShift Container Platform 4.21</ProductName>
        <ReleaseDate>2026-05-26T00:00:00Z</ReleaseDate>
        <Advisory type="RHBA" url="https://access.redhat.com/errata/RHBA-2026:20032">RHBA-2026:20032</Advisory>
        <Package name="kernel">kernel-0:5.14.0-570.116.1.el9_6</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:openshift:4.21::el8">
        <ProductName>Red Hat OpenShift Container Platform 4.21</ProductName>
        <ReleaseDate>2026-05-26T00:00:00Z</ReleaseDate>
        <Advisory type="RHBA" url="https://access.redhat.com/errata/RHBA-2026:20032">RHBA-2026:20032</Advisory>
        <Package name="openshift">openshift-0:4.21.0-202605142021.p2.geab2218.assembly.stream.el10</Package>
    </AffectedRelease>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:6">
        <ProductName>Red Hat Enterprise Linux 6</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>kernel</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:7">
        <ProductName>Red Hat Enterprise Linux 7</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>kernel</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:7">
        <ProductName>Red Hat Enterprise Linux 7</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>kernel-rt</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-46300
https://nvd.nist.gov/vuln/detail/CVE-2026-46300
    </References>
    <CSAw>True</CSAw>
</Vulnerability>