TLDR: Exploit. This is a deterministic local privilege escalation affecting the default install of the latest Arch, Fedora, Debian, Amazon Linux and RHEL distributions, having unprivileged user namespaces enabled, openvswitch auto-loading, and a stock kernel carrying the Fragnesia fix. The issue has been public since 08/13/2026 on netdev, and the fix landed in mainline and shipped in stable on 09/04/2026.
The skb that wasn't freed - the Fragnesia primitive via Open vSwitch
About this summary. This is a short, independently written summary of an article first published by Doyensec. Cyber Security News did not report or verify the underlying story. Read the original: https://blog.doyensec.com/2026/09/17/ovs.html
Source attribution: headline and facts are from Doyensec (blog.doyensec.com). Summary method: excerpt of the source description. See our source attribution policy.


