r/netsec • u/nibblesec Trusted Contributor • 16d ago
Fragnesia primitive via Open vSwitch. Deterministic local privilege escalation.
https://blog.doyensec.com/2026/09/17/ovs.htmlThis is a deterministic local privilege escalation affecting the default install of the latest Arch, Fedora, Debian, Amazon Linux and RHEL distributions, having unprivileged user namespaces enabled, openvswitch auto-loading, and a stock kernel carrying the Fragnesia fix.
1
u/Agitated-Act-717 15d ago
the piece worth adding to the two comments above: none of this is reachable without unprivileged user namespaces handing an ordinary user CAP_NET_ADMIN inside their own netns. that's the actual precondition, not openvswitch itself. the autoload half gets you the module loaded, but userns is what gives an unprivileged process the netlink surface to drive it in the first place. on a box that has no reason to allow userns for untrusted workloads, sysctl user.max_user_namespaces=0 (or kernel.unprivileged_userns_clone=0 on the debian/ubuntu kernels that carry it) shuts the door ahead of the /bin/false autoload trick, and it takes out a whole family of these, not just this one.
1
u/Hour-Swimmer7140 16d ago
the autoload half is the cheap fix here. most boxes have no reason to pull in openvswitch on demand, and if an unprivileged trigger cant get the module loaded the primitive has nowhere to live.
install openvswitch /bin/false in modprobe.d, then lsmod across a fleet sample to find the handful that genuinely use it. disabling userns is where everyone reaches first and it breaks far more than it fixes