CVE-2026-31431
crypto: algif_aead - Revert to operating out-of-place
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.
Coverage 3 sources
-
2026-04-30
Help Net Security
high
Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431)
Linux kernel flaw (CVE-2026-31431) enables local privilege escalation on most Linux distributions since 2017.
-
2026-05-01
CISA Cybersecurity Advisories
critical
CISA Adds One Known Exploited Vulnerability to Catalog
CISA adds CVE-2026-31431 to its Known Exploited Vulnerabilities Catalog due to active exploitation.
-
2026-05-02
Microsoft Security Blog
critical
CVE-2026-31431: Copy Fail vulnerability enables Linux root privilege escalation across cloud environments
Linux vulnerability CVE-2026-31431 enables root privilege escalation across cloud environments.
-
2026-07-14
CISA Cybersecurity Advisories
high
ABB Ability Edgenius
ABB reports a vulnerability in Ability Edgenius that allows local privilege escalation.
-
2026-09-17
CISA Cybersecurity Advisories
high
ABB Ability Edgenius
ABB reports a vulnerability in Ability Edgenius that allows local privilege escalation.
-
2026-09-22
CISA Cybersecurity Advisories
medium
Siemens SIPLUS and SIMATIC Products
Siemens SIPLUS and SIMATIC products are vulnerable to the 'Copy Fail' vulnerability, with fixes available for some affected versions.
Also covered
- CVE-2026-86950 Apple iOS and iPadOS
- CVE-2023-6548 Cloud Software Group NetScaler ADC
- CVE-2023-25608 Fortinet FortiAP-W2
- CVE-2026-88772 Memory overflow vulnerability leading to Remote Code Execution or Denial of Service
- CVE-2026-88771 A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands