CVE-2026-31431
crypto: algif_aead - Revert to operating out-of-place
Description
ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported vulnerability. CVE‑2026‑31431 (Copy Fail) is a Linux kernel vulnerability that may allow a locally authenticated user or compromised container workload to gain elevated (root) privileges on affected systems. Once root access is obtained, the attacker can effectively gain complete control of the system
In plain language
AI Act nowThis is a Linux kernel flaw that can let a local attacker gain higher privileges on your server; if you’re running affected Linux kernels, you should update now—especially because it’s been added to the CISA Known Exploited Vulnerabilities list.
CVE-2026-31431 is a Linux kernel privilege-escalation flaw in the algif_aead module caused by improper handling of in-place crypto operations; it is listed in CISA KEV, meaning it’s been observed in real environments and should be treated as actively risk-bearing once reachable from a low-privilege position.
What to do now
- Check whether your systems run an affected Linux kernel (on each host, confirm the exact kernel version).
- If you find you’re affected, plan a kernel upgrade to a fixed revision or fixed kernel package as soon as possible.
- Upgrade Linux kernel to one of the fixed revisions listed by upstream (example fixed git revision: 893d22e0135fa394db81df88697fba6032747667), or to the distro’s fixed kernel build (e.g., Ubuntu/Debian/RHEL/Amazon Linux/OpenShift releases that include the fix).
- After upgrading, verify the running kernel version matches the upgraded (fixed) one and confirm the machine reboots into the updated kernel.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
References
- Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministryen·The Hacker News· Incident Hermes AI agent ai-ml
- 15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distrosen·The Hacker News· PoC privilege-escalation
- New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Androiden·The Hacker News· PoC linux kernel privilege-escalation
- Linux-уязвимость DirtyClone помогает повысить права до уровня rootru-ru·Хакер (xakep.ru)· PoC Linux kernel privilege-escalation
- New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packetsen·The Hacker News· PoC Linux Kernel rce
- Июньский «В тренде VM»: уязвимости ядра Linux, Microsoft Defender и устройств Palo Alto Networksru·Хабр — Информационная безопасность· Roundup Linux kernel
- Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Modelsen·The Hacker News· PoC open-weight LLM ai-ml
- В фокусе RVD: трендовые уязвимости маяru·Хабр — Информационная безопасность· Exploited PAN-OS rce
- Metasploit Wrap Up 05/22/2026en·Rapid7 Blog· PoC Cisco Catalyst SD-WAN Controller auth-bypass
- Майский «В тренде VM»: громкие уязвимости в Linux, ActiveMQ, SharePoint и Acrobat Readerru·Positive Technologies (Хабр)· Roundup Linux kernel privilege-escalation
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-31431 and every CVE in our database. Create a free account — no credit card required.
Create Free Account