• News/
  • zdnet-b8e46dc1-6866-4ea4-8e39-43e2723544f5

The third major Linux kernel flaw in two weeks has been found - thanks to AI

ZDNet
·
Steven Vaughan-Nichols
·
Published May 14, 2026
·
Updated

Follow ZDNET: Add us as a preferred source on Google. According to Linus's law, "Given enough eyeballs, all bugs are shallow," is fundamental to open source. Unfortunately, thanks to AI bug-finding tools, such as Claude Mythos and OpenAI Daybreak, behind most of those eyeballs are AI engines, and they're proving to be much faster at finding security problems than human ones. Also: Linux is getting a security wake-up call - why it was inevitable and I'm not worried So it is the latest serious Linux kernel vulnerability, Fragnesia, has emerged. It's the third serious local root flaw in the last two weeks. Following in the footsteps of Copy Fail and Dirty Frag, this page-cache corruption bug gives unprivileged users a reliable path to full root control on affected systems. And what are those systems, you ask? According to AlmaLinux, Fragnesia immediately yields root on all major distributions. So, essentially, all Linux distros can be targeted and successfully hacked. Are we having fun yet or what? Also: Dirty Frag is a new Linux bug putting your system at risk - and there's no easy fix yet The bug was disclosed this week by the AI security company Zellic, with William Bowling and other researchers using the company's AI-agentic software auditing tool, V12. It works by abusing a logic bug in the Linux XFRM (short for "transform") ESP-in-TCP subsystem to write arbitrary bytes into the kernel page cache of read-only files, without requiring any race condition. This opens the door ...

Read full article

Affected Software

2 affected components
Linux Kernel
Linux XFRM ESP-in-TCP subsystem
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a new Linux kernel flaw discovered through AI tools.

2

What security implications are discussed in the article?

The article highlights vulnerabilities in the Linux kernel and its potential impact on system security.

3

What products or software are affected by this vulnerability?

The vulnerabilities affect the Linux kernel and the Linux XFRM ESP-in-TCP subsystem.

4

How does AI contribute to finding these vulnerabilities?

AI bug-finding tools have played a significant role in detecting recent flaws in the Linux kernel.

5

How frequently are vulnerabilities being discovered in the Linux kernel?

This article notes that three major vulnerabilities have been found in the Linux kernel within the last two weeks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203