Linux admins reeling from handling last month’s kernel vulnerabilities have a new headache to deal with: Fragnesia.
“This is a significant vulnerability,” , and others are pushing out patches or mitigations; Linux users and organizations to apply the patch as soon as possible by running update tools. If patching is not possible at this point, consider applying the same mitigations as for Dirty Frag, such as assessing whether esp4, esp6, and related xfrm/IPsec functionality can be temporarily disabled safely, restricting unnecessary local shell access, hardening containerized workloads, and increasing monitoring for abnormal privilege escalation activity.
Related content: Kill switch for Linux kernel features proposed to improve security
Beggs advises system administrators to confirm kernel exposure by reviewing version numbers, and then update to a patched kernel if necessary and reboot the affected system. If ESP-in-TCP is not required, disable the module and block its use; this mitigation can also be immediately applied until patching is complete. Because the vulnerability requires local access, make sure that basic steps such as enforcing MFA for privileged accounts, disabling of unneeded shell access, and enforcing least privilege are all in place.
Beggs also said admins may wish to increase monitoring of privileged processes (PAM, systemd, cron) and look for unexpected restarts, unexpected config reloads, and sudden privilege escalations.
SOCIAL SHARE CARD GENERATOR