logo

U.S. CISA adds a flaw in Linux Kernel to its Known Exploited Vulnerabilities catalog

ID: 8e3613bf-53af-5654-b9cd-bf0bd2eaffbe

STIX ID: report--8e3613bf-53af-5654-b9cd-bf0bd2eaffbe

Feed Name: Security Affairs

Threat Score
92/100

Date Published: 2026-05-04

Date Updated: 2026-05-05

Author: Pierluigi Paganini

...
...

CVE-2026-31431 (“Copy Fail”) is a logic flaw in the Linux kernel crypto template (authencesn) combined with AF_ALG and splice() that allows an unprivileged local attacker to perform deterministic 4-byte writes into the page cache of any readable file, enabling stealthy modification of in-memory setuid binaries (e.g., /usr/bin/su) and resulting in local root escalation and cross-container escapes; researchers published a 732-byte PoC and CISA added the issue to its Known Exploited Vulnerabilities catalog with mandatory fixes ordered for federal agencies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.