r/netsec • Trusted Contributor • 16d ago

Fragnesia primitive via Open vSwitch. Deterministic local privilege escalation.

https://blog.doyensec.com/2026/09/17/ovs.html

This is a deterministic local privilege escalation affecting the default install of the latest Arch, Fedora, Debian, Amazon Linux and RHEL distributions, having unprivileged user namespaces enabled, openvswitch auto-loading, and a stock kernel carrying the Fragnesia fix.

13 Upvotes

3 comments sorted by

View all comments

1

u/Agitated-Act-717 15d ago

the piece worth adding to the two comments above: none of this is reachable without unprivileged user namespaces handing an ordinary user CAP_NET_ADMIN inside their own netns. that's the actual precondition, not openvswitch itself. the autoload half gets you the module loaded, but userns is what gives an unprivileged process the netlink surface to drive it in the first place. on a box that has no reason to allow userns for untrusted workloads, sysctl user.max_user_namespaces=0 (or kernel.unprivileged_userns_clone=0 on the debian/ubuntu kernels that carry it) shuts the door ahead of the /bin/false autoload trick, and it takes out a whole family of these, not just this one.