U.S. CISA adds a flaw in Linux Kernel to its Known Exploited Vulnerabilities catalog
ID: 8e3613bf-53af-5654-b9cd-bf0bd2eaffbe
STIX ID: report--8e3613bf-53af-5654-b9cd-bf0bd2eaffbe
Feed Name: Security Affairs
CVE-2026-31431 (“Copy Fail”) is a logic flaw in the Linux kernel crypto template (authencesn) combined with AF_ALG and splice() that allows an unprivileged local attacker to perform deterministic 4-byte writes into the page cache of any readable file, enabling stealthy modification of in-memory setuid binaries (e.g., /usr/bin/su) and resulting in local root escalation and cross-container escapes; researchers published a 732-byte PoC and CISA added the issue to its Known Exploited Vulnerabilities catalog with mandatory fixes ordered for federal agencies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
