The skb that wasn't freed - the Fragnesia primitive via Open vSwitch
Summary
Doyensec details a deterministic local privilege escalation in Linux Open vSwitch, stemming from a frag/zerocopy marker being stripped and allowing in-place ESP decryption on page-cache fragments. The post links multiple CVEs (CVE-2026-90049, CVE-2026-89487, CVE-2026-80977), explains the Open vSwitch architecture, and outlines root cause analysis, exploitation flow, and mitigations. It also covers patch timelines and practical hardening steps for admins.