网安资讯详情 - SecLens 情报雷达

网安资讯,一网打尽。汇集权威漏洞通告与行业要闻,结合分组浏览、智能过滤、RSS订阅 和 Webhook 推送,多通道拓展您的安全情报视野。

Fragnesia Local Privilege Escalation report via ESP-in-TCP in the Linux Kernel

来源: aws_security_bulletins · 发布时间 2026-05-14 10:17 (UTC+08:00) · 抓取时间 2026-05-14 11:15 (UTC+08:00)

原文链接

摘要

This is an ongoing issue. Information is subject to change. Please refer to our Security Bulletin (ID: 2026-030-AWS) for the most updated patching information.

正文

Bulletin ID: 2026-029-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 05/13/2026 18:45 PM PDT This is an ongoing issue. Information is subject to change. Please refer to our Security Bulletin (ID: 2026-030-AWS) for the most updated patching information. Description: Amazon is aware of CVE-2026-46300, a report of an additional privilege escalation issue in the Linux kernel related to the DirtyFrag, copy.fail class of issues (CVE-2026-43284). The proof of concept uses a vector via the loadable module espintcp. Amazon Linux does not provide this module, and is not affected. As defense in depth we will include a correctness patch to the core networking code to harden against possible similar issues in network protocol implementations that rely on this behavior.

标签

扩展字段

{
  "author": "[email protected]",
  "bulletin_id": "2026-029-AWS",
  "content_type": "Important (requires attention)",
  "details": {
    "Bulletin ID": "2026-029-AWS",
    "Content Type": "Important (requires attention)",
    "Publication Date": "05/13/2026 18:45 PM PDT",
    "Scope": "AWS"
  },
  "publication_detail": "05/13/2026 18:45 PM PDT",
  "scope": "AWS"
}