Fragnesia Local Privilege Escalation report via ESP-in-TCP in the Linux Kernel
UnratedCVE-2026-46300 · Published May 13, 2026 · updated Sep 25, 2026
Bulletin ID: 2026-029-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 05/13/2026 13:45 PM PDT Last Updated Date: 05/14/2026 13:45 PM PDT ⚠️This is an ongoing issue. Information is subject to change. Please refer to our Security Bulletin (ID: 2026-030-AWS) for the most updated patching information. Description: Amazon is aware of CVE-2026-46300 , a report of an additional privilege escalation issue in the Linux kernel related to the DirtyFrag/copy.fail class of issues ( CVE-2026-43284 ). The proof of concept uses a vector via the loadable module espintcp. Amazon Linux and Bottlerocket don't provide this module, and are not affected. As defense in depth we will include a correctness patch to the core networking code to harden against possible similar issues in network protocol implementations that rely on this behavior. Related Security Bulletins - copy.fail variants: Security Bulletin 2026-027-AWS - CVE-2026-43284 and CVE-2026-31431 (also known as "DirtyFrag" or copy.fail 2) Security Bulletin 2026-026-AWS - CVE-2026-31431 (also known as copy.fail) References: https://github.com/v12-security/pocs/tree/main/fragnesia "Dirty Fra...
Affected versions
Details and references
Bulletin ID: 2026-029-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 05/13/2026 13:45 PM PDT Last Updated Date: 05/14/2026 13:45 PM PDT ⚠️This is an ongoing issue. Information is subject to change. Please refer to our Security Bulletin (ID: 2026-030-AWS) for the most updated patching information. Description: Amazon is aware of CVE-2026-46300 , a report of an additional privilege escalation issue in the Linux kernel related to the DirtyFrag/copy.fail class of issues ( CVE-2026-43284 ). The proof of concept uses a vector via the loadable module espintcp. Amazon Linux and Bottlerocket don't provide this module, and are not affected. As defense in depth we will include a correctness patch to the core networking code to harden against possible similar issues in network protocol implementations that rely on this behavior. Related Security Bulletins - copy.fail variants: Security Bulletin 2026-027-AWS - CVE-2026-43284 and CVE-2026-31431 (also known as "DirtyFrag" or copy.fail 2) Security Bulletin 2026-026-AWS - CVE-2026-31431 (also known as copy.fail) References: https://github.com/v12-security/pocs/tree/main/fragnesia "Dirty Frag" and other issues in Amazon Linux kernels Please email aws-security@amazon.com with any security questions or concerns. "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-029-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} "Fragnesia" Local Privilege Escalation report via ESP-in-TCP in the Linux Kernel (CVE-2026-46300) Bulletin ID: 2026-029-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 05/13/2026 13:45 PM PDT Last Updated Date: 05/14/2026 13:45 PM PDT ⚠️This is an ongoing issue. Information is subject to change. Please refer to our Security Bulletin (ID: 2026-030-AWS) for the most updated patching information. Description: Amazon is aware of CVE-2026-46300 , a report of an additional privilege escalation issue in the Linux kernel related to the DirtyFrag/copy.fail class of issues ( CVE-2026-43284 ). The proof of concept uses a vector via the loadable module espintcp. Amazon Linux and Bottlerocket don't provide this module, and are not affected. As defense in depth we will include a correctness patch to the core networking code to harden against possible similar issues in network protocol implementations that rely on this behavior. Related Security Bulletins - copy.fail variants: Security Bulletin 2026-027-AWS - CVE-2026-43284 and CVE-2026-31431 (also known as "DirtyFrag" or copy.fail 2) Security Bulletin 2026-026-AWS - CVE-2026-31431 (also known as copy.fail) References: https://github.com/v12-security/pocs/tree/main/fragnesia "Dirty Frag" and other issues in Amazon Linux kernels Please email aws-security@amazon.com with any security questions or concerns. {"data":{"items":[{"fields":{"footer":"{ "createAccountButtonLabel": "Create an AWS account", "createAccountButtonURL": "https://signin.aws.amazon.com/signup?request_type=register", "backToTopText": "Back to top", "eoeText": "Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disabil
- Severity from
- no source yet
- Also known as
- CVE-2026-43284, CVE-2026-31431
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 18 | Remote Code Execution in amazon-redshift-python-driver | Unrated | No fix yet |
| May 14 | Missing integrity verification in Triton inference handler in Amazon SageMaker Python SDK | Medium6.4 | v2.257.2andv3.8.0 |
| May 14 | Issue with Amazon SageMaker Python SDK - Model artifact integrity verification issues... | Unrated | No fix yet |
| May 14 | Heap out-of-bounds read in coreMQTT MQTT5 property parsing | Unrated | No fix yet |
| May 13 | Ongoing updates on Copy.fail and variants | Unrated | No fix yet |
| May 8 | Remote Code Execution via Unsafe Class Loading in Amazon Redshift JDBC Driver | Unrated | No fix yet |