# Fragnesia - CVE-2026-46300

**URL:** <https://forums.rockylinux.org/t/fragnesia-cve-2026-46300/20463>\
**Category:** Rocky Linux Help & Support\
**Created:** [May 14, 2026, 2:07am UTC](https://forums.rockylinux.org/t/fragnesia-cve-2026-46300/20463 "2026-05-14T02:07:08Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Challvy](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/challvy/32/6130_2.png) [@Challvy](https://forums.rockylinux.org/u/Challvy)\
**Post date:** [May 14, 2026, 2:07am UTC](https://forums.rockylinux.org/t/fragnesia-cve-2026-46300/20463/1 "2026-05-14T02:07:09Z")

</div>

If Rocky Linux is affected by this CVE-2026-46300

POC: [pocs/fragnesia/README.md at main · v12-security/pocs · GitHub](https://github.com/v12-security/pocs/blob/main/fragnesia/README.md)

---

<div class="post-metadata">

**Author:** ![discourse\_ai\_spam](https://avatars.discourse-cdn.com/v4/letter/d/c68b51/32.png) [@discourse\_ai\_spam](https://forums.rockylinux.org/u/discourse_ai_spam)\
**Post date:** [May 14, 2026, 2:07am UTC](https://forums.rockylinux.org/t/fragnesia-cve-2026-46300/20463/2 "2026-05-14T02:07:11Z")

</div>



---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex020/uploads/rockylinux/original/1X/91b7219eec10e30013422e4df76c1d898711a5d5.svg) [@system](https://forums.rockylinux.org/u/system)\
**Post date:** [May 14, 2026, 3:07am UTC](https://forums.rockylinux.org/t/fragnesia-cve-2026-46300/20463/3 "2026-05-14T03:07:13Z")

</div>



---

<div class="post-metadata">

**Author:** ![linde](https://avatars.discourse-cdn.com/v4/letter/l/e36b37/32.png) [@linde](https://forums.rockylinux.org/u/linde)\
**Post date:** [May 14, 2026, 3:34am UTC](https://forums.rockylinux.org/t/fragnesia-cve-2026-46300/20463/4 "2026-05-14T03:34:13Z")

</div>

If the github link is accurate, then this vulnerability would affect Rocky Linux (because Rocky was vulnerable to DirtyFrag).

Rocky has patched kernels available in the new security repo; run `dnf update` to get the latest repo definitions, then `dnf --enablerepo=security update` to get the patched kernel, then reboot to run the patched kernel.

Also according to the link, the _mitigation_ is the same as for DirtyFrag – useful if you can’t reboot immediately.

Edit: It doesn’t necessarily follow that Rocky’s DirtyFrag patch fixes this one. After further reading, I’m _guessing_ it doesn’t.

---

<div class="post-metadata">

**Author:** ![joshwhiteside](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/joshwhiteside/32/2725_2.png) [@joshwhiteside](https://forums.rockylinux.org/u/joshwhiteside)\
**Post date:** [May 14, 2026, 8:20am UTC](https://forums.rockylinux.org/t/fragnesia-cve-2026-46300/20463/5 "2026-05-14T08:20:48Z")

</div>

I’ve just attempted this on Rocky 8.10 with the latest kernel installed from the new security repo and has given me root access

---

<div class="post-metadata">

**Author:** ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)\
**Post date:** [May 14, 2026, 9:45am UTC](https://forums.rockylinux.org/t/fragnesia-cve-2026-46300/20463/6 "2026-05-14T09:45:25Z")

</div>

Yep, it requires an additional fix, so all versions are affected. There’s already a RHEL page for this that shows what is affected. I guess a fix will appear in the next couple of days.

---

<div class="post-metadata">

**Author:** ![Challvy](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/challvy/32/6130_2.png) [@Challvy](https://forums.rockylinux.org/u/Challvy)\
**Post date:** [May 14, 2026, 10:09am UTC](https://forums.rockylinux.org/t/fragnesia-cve-2026-46300/20463/7 "2026-05-14T10:09:21Z")

</div>

The kernel patch is different: [net: skbuff: preserve shared-frag marker during coalescing](https://lore.kernel.org/netdev/20260513041635.1289541-1-vakzz@zellic.io/)

So it requires an additional fix as @iwalker said.

---

<div class="post-metadata">

**Author:** ![long.cheung](https://avatars.discourse-cdn.com/v4/letter/l/77aa72/32.png) [@long.cheung](https://forums.rockylinux.org/u/long.cheung)\
**Post date:** [May 18, 2026, 2:23am UTC](https://forums.rockylinux.org/t/fragnesia-cve-2026-46300/20463/8 "2026-05-18T02:23:52Z")

</div>

any update? still no fix?

---

<div class="post-metadata">

**Author:** ![rsathishkumarr](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/rsathishkumarr/32/6136_2.png) [@rsathishkumarr](https://forums.rockylinux.org/u/rsathishkumarr)\
**Post date:** [May 18, 2026, 10:19am UTC](https://forums.rockylinux.org/t/fragnesia-cve-2026-46300/20463/9 "2026-05-18T10:19:45Z")

</div>

@iwalker Following up on this, could you please share the ETA for the fix?

---

<div class="post-metadata">

**Author:** ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)\
**Post date:** [May 18, 2026, 10:20am UTC](https://forums.rockylinux.org/t/fragnesia-cve-2026-46300/20463/10 "2026-05-18T10:20:53Z")

</div>

Well Red Hat haven’t even released a fix yet, but I’ve posted an internal message to find out if our team has an ETA for an interim fix.

---

<div class="post-metadata">

**Author:** ![mneveu](https://avatars.discourse-cdn.com/v4/letter/m/71c47a/32.png) [@mneveu](https://forums.rockylinux.org/u/mneveu)\
**Post date:** [May 19, 2026, 11:26am UTC](https://forums.rockylinux.org/t/fragnesia-cve-2026-46300/20463/11 "2026-05-19T11:26:09Z")

</div>

Hello,  
Is it fixed by kernel-\*-5.14.0-611.55.1.el9\_7.0.3.x86\_64.rpm just now available on [Rocky Linux Repository](https://download.rockylinux.org/pub/rocky/9/security/x86_64/os/Packages/k/) ?  
Where can I find what is fixed with this version ? There is nothing on product errata ([Rocky Enterprise Software Foundation Product Errata](https://errata.rockylinux.org/))

---

<div class="post-metadata">

**Author:** ![Logan](https://avatars.discourse-cdn.com/v4/letter/l/278dde/32.png) [@Logan](https://forums.rockylinux.org/u/Logan)\
**Post date:** [May 19, 2026, 11:45am UTC](https://forums.rockylinux.org/t/fragnesia-cve-2026-46300/20463/12 "2026-05-19T11:45:08Z")

</div>

> Yes.
> 
> Changelog for kernel-5.14.0-611.55.1.el9\_7.0.3.x86\_64
> 
> - Mon May 18 2026 Jonathan Dieter [jdieter@resf.org](mailto:jdieter@resf.org) - 5.14.0-611.55.1.0.3
> 
> - ptrace: slightly saner ‘get\_dumpable()’ logic (Roxana Nicolescu) [ciqres] {CVE-2026-46333}
> 
> - Thu May 14 2026 Jonathan Dieter [jdieter@resf.org](mailto:jdieter@resf.org) - 5.14.0-611.55.1.0.2
> 
> - net: skbuff: propagate shared-frag marker through frag-transfer helpers (Hyunwoo Kim) [ciqres] {CVE-2026-46300}
> 
> - Drop rxrpc patches since upstream has decided not to carry them. Users of kernel-modules-partner are now  
> vulnerable to CVE-2026-43500, but the package is only available in the unsupported devel repo

---

<div class="post-metadata">

**Author:** ![mneveu](https://avatars.discourse-cdn.com/v4/letter/m/71c47a/32.png) [@mneveu](https://forums.rockylinux.org/u/mneveu)\
**Post date:** [May 19, 2026, 11:50am UTC](https://forums.rockylinux.org/t/fragnesia-cve-2026-46300/20463/13 "2026-05-19T11:50:17Z")

</div>

Thanks !  
Where you have founded this changelog ? 🙂

---

<div class="post-metadata">

**Author:** ![Logan](https://avatars.discourse-cdn.com/v4/letter/l/278dde/32.png) [@Logan](https://forums.rockylinux.org/u/Logan)\
**Post date:** [May 19, 2026, 11:59am UTC](https://forums.rockylinux.org/t/fragnesia-cve-2026-46300/20463/14 "2026-05-19T11:59:21Z")

</div>

> dnf repoquery --changelog kernel-5.14.0-611.55.1.el9\_7.0.3

---

<div class="post-metadata">

**Author:** ![kristino](https://avatars.discourse-cdn.com/v4/letter/k/c77e96/32.png) [@kristino](https://forums.rockylinux.org/u/kristino)\
**Post date:** [May 19, 2026, 5:14pm UTC](https://forums.rockylinux.org/t/fragnesia-cve-2026-46300/20463/15 "2026-05-19T17:14:33Z")

</div>

Hi ! My Rocky 9’s get the kernel-5.14.0-611.55.1.el9\_7.0.3.x86\_64 from the new security-repo now, but there are no new packaces for Rocky 8 in this repo. Does anyone know if there will be a fix for CVE-2026-46300 for Rocky 8 ?

---

<div class="post-metadata">

**Author:** ![doublem](https://avatars.discourse-cdn.com/v4/letter/d/ccd318/32.png) [@doublem](https://forums.rockylinux.org/u/doublem)\
**Post date:** [May 19, 2026, 5:23pm UTC](https://forums.rockylinux.org/t/fragnesia-cve-2026-46300/20463/16 "2026-05-19T17:23:24Z")

</div>

Is it possible to have a web page or a sticky forum thread to follow the Rocky specific “Security releases” ? It is hard to keep track or find out the information of all the versions.

Things to include in the information could be (for each Rocky release, 8,9,10, …):  
latest version of rocky security kernel, what have been fixed in this version, latest RHEL/upstream kernel, additional thing to do if needed (to fix security issues).

---

<div class="post-metadata">

**Author:** ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)\
**Post date:** [May 20, 2026, 7:13am UTC](https://forums.rockylinux.org/t/fragnesia-cve-2026-46300/20463/17 "2026-05-20T07:13:27Z")

</div>

> [@doublem](#):
>
> Is it possible to have a web page or a sticky forum thread to follow the Rocky specific “Security releases” ? It is hard to keep track or find out the information of all the versions.

This would be pointless since the errata should have all the security information anyway and generated automatically. I’ll raise it internally to find out why the errata is not up-to-date and what we plan on doing about that. To do something additional then means spending more time on something else doing all of that manually collating it and preparing a webpage, etc. Unless someone wants to volunteer and do that? Otherwise, there are far more important things for the team to spend their time on.

---

<div class="post-metadata">

**Author:** ![rsathishkumarr](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/rsathishkumarr/32/6136_2.png) [@rsathishkumarr](https://forums.rockylinux.org/u/rsathishkumarr)\
**Post date:** [May 20, 2026, 8:05am UTC](https://forums.rockylinux.org/t/fragnesia-cve-2026-46300/20463/18 "2026-05-20T08:05:11Z")

</div>

Is a fix currently available for Rocky 8.10? I don’t see any version newer than 4.18.0-553.123.1.el8\_10.0.1 for Rocky 8.10

---

<div class="post-metadata">

**Author:** ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)\
**Post date:** [May 20, 2026, 8:11am UTC](https://forums.rockylinux.org/t/fragnesia-cve-2026-46300/20463/19 "2026-05-20T08:11:38Z")

</div>

Yes there is, but you will have to enable the security repository to get the fix. This is the interim fix, which is patched versions of existing kernels. Red Hat haven’t even patched RHEL8 yet so this is why there is no fix in the standard base repositories.

---

<div class="post-metadata">

**Author:** ![rsathishkumarr](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/rsathishkumarr/32/6136_2.png) [@rsathishkumarr](https://forums.rockylinux.org/u/rsathishkumarr)\
**Post date:** [May 20, 2026, 8:16am UTC](https://forums.rockylinux.org/t/fragnesia-cve-2026-46300/20463/20 "2026-05-20T08:16:29Z")

</div>

have already enabled the security repo and this is what i see

```  
$ dnf list kernel  
Last metadata expiration check: 0:12:16 ago on Wed May 20 08:03:08 2026.  
Installed Packages  
kernel.x86\_64 4.18.0-553.40.1.el8\_10 @baseos  
kernel.x86\_64 4.18.0-553.123.1.el8\_10.0.1 @security  
```

[Next page](https://forums.rockylinux.org/t/fragnesia-cve-2026-46300/20463.md?page=2)
