Skip to content
AWSAWS-2026-029

Fragnesia Local Privilege Escalation report via ESP-in-TCP in the Linux Kernel

UnratedCVE-2026-46300 · Published May 13, 2026 · updated Sep 25, 2026

Bulletin ID: 2026-029-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 05/13/2026 13:45 PM PDT Last Updated Date: 05/14/2026 13:45 PM PDT   ⚠️This is an ongoing issue. Information is subject to change. Please refer to our Security Bulletin (ID: 2026-030-AWS) for the most updated patching information. Description: Amazon is aware of  CVE-2026-46300 , a report of an additional privilege escalation issue in the Linux kernel related to the DirtyFrag/copy.fail class of issues ( CVE-2026-43284 ). The proof of concept uses a vector via the loadable module espintcp. Amazon Linux and Bottlerocket don't provide this module, and are not affected. As defense in depth we will include a correctness patch to the core networking code to harden against possible similar issues in network protocol implementations that rely on this behavior. Related Security Bulletins - copy.fail variants: Security Bulletin 2026-027-AWS - CVE-2026-43284 and CVE-2026-31431 (also known as "DirtyFrag" or copy.fail 2) Security Bulletin 2026-026-AWS - CVE-2026-31431 (also known as copy.fail) References: https://github.com/v12-security/pocs/tree/main/fragnesia "Dirty Fra...

AWS advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

Bulletin ID: 2026-029-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 05/13/2026 13:45 PM PDT Last Updated Date: 05/14/2026 13:45 PM PDT   ⚠️This is an ongoing issue. Information is subject to change. Please refer to our Security Bulletin (ID: 2026-030-AWS) for the most updated patching information. Description: Amazon is aware of  CVE-2026-46300 , a report of an additional privilege escalation issue in the Linux kernel related to the DirtyFrag/copy.fail class of issues ( CVE-2026-43284 ). The proof of concept uses a vector via the loadable module espintcp. Amazon Linux and Bottlerocket don't provide this module, and are not affected. As defense in depth we will include a correctness patch to the core networking code to harden against possible similar issues in network protocol implementations that rely on this behavior. Related Security Bulletins - copy.fail variants: Security Bulletin 2026-027-AWS - CVE-2026-43284 and CVE-2026-31431 (also known as "DirtyFrag" or copy.fail 2) Security Bulletin 2026-026-AWS - CVE-2026-31431 (also known as copy.fail) References: https://github.com/v12-security/pocs/tree/main/fragnesia "Dirty Frag" and other issues in Amazon Linux kernels Please email aws-security@amazon.com with any security questions or concerns.   "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-029-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} "Fragnesia" Local Privilege Escalation report via ESP-in-TCP in the Linux Kernel (CVE-2026-46300) Bulletin ID: 2026-029-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 05/13/2026 13:45 PM PDT Last Updated Date: 05/14/2026 13:45 PM PDT   ⚠️This is an ongoing issue. Information is subject to change. Please refer to our Security Bulletin (ID: 2026-030-AWS) for the most updated patching information. Description: Amazon is aware of  CVE-2026-46300 , a report of an additional privilege escalation issue in the Linux kernel related to the DirtyFrag/copy.fail class of issues ( CVE-2026-43284 ). The proof of concept uses a vector via the loadable module espintcp. Amazon Linux and Bottlerocket don't provide this module, and are not affected. As defense in depth we will include a correctness patch to the core networking code to harden against possible similar issues in network protocol implementations that rely on this behavior. Related Security Bulletins - copy.fail variants: Security Bulletin 2026-027-AWS - CVE-2026-43284 and CVE-2026-31431 (also known as "DirtyFrag" or copy.fail 2) Security Bulletin 2026-026-AWS - CVE-2026-31431 (also known as copy.fail) References: https://github.com/v12-security/pocs/tree/main/fragnesia "Dirty Frag" and other issues in Amazon Linux kernels Please email aws-security@amazon.com with any security questions or concerns.   {"data":{"items":[{"fields":{"footer":"{ "createAccountButtonLabel": "Create an AWS account", "createAccountButtonURL": "https://signin.aws.amazon.com/signup?request_type=register", "backToTopText": "Back to top", "eoeText": "Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disabil

Severity from
no source yet
Also known as
CVE-2026-43284, CVE-2026-31431

More AWS advisories

All AWS
Advisory
Remote Code Execution in amazon-redshift-python-driver
UnratedMay 18
Missing integrity verification in Triton inference handler in Amazon SageMaker Python SDK
Medium6.4May 14
Issue with Amazon SageMaker Python SDK - Model artifact integrity verification issues...
UnratedMay 14
Heap out-of-bounds read in coreMQTT MQTT5 property parsing
UnratedMay 14
Ongoing updates on Copy.fail and variants
UnratedMay 13
Remote Code Execution via Unsafe Class Loading in Amazon Redshift JDBC Driver
UnratedMay 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.