Fragnesia CVE-2026-46300 skb_try_coalesce SKBFL_SHARED_FRAG LPE Detection
Detects suspicious process execution patterns associated with the exploitation of CVE-2026-46300 (Fragnesia). The rule monitors for the combination of user namespace creation via unshare, network tunnel configuration via ip, and kernel module loading related to ESP or rxrpc, which are indicative of an attempt to trigger a privilege escalation vulnerability in the Linux kernel.
Splunk (SPL)

