New stable kernels landed today in Alpine Linux. They address the Fragnesia CVE (CVE-2026-46300), and the vulnerabilities that came before it.

- 6.18.31
- 6.12.89
- 6.6.139
- 5.15.207
- 5.10.256

These have been backported all the way down to Alpine Linux 3.16.

Follow

@alpinelinux Haven't checked the others, but at least 6.12.89 doesn't address Fragnesia yet. Haven't you mixed it up with ssh-keysign-pwn / CVE-2026-46333 which it does fix?

@dos You are right, checked the commit logs of each branch, and it includes 'ptrace: slightly saner 'get_dumpable()' logic', which is indeed about ssh-keysign-pwn.

I've edited the post to make that clear.

Sign in to participate in the conversation
Librem Social

Librem Social is an opt-in public network. Messages are shared under Creative Commons BY-SA 4.0 license terms. Policy.

Stay safe. Please abide by our code of conduct.

(Source code)

image/svg+xml Librem Chat image/svg+xml