logo

Nine-Year-Old Zero-Day Flaw in Linux Kernel Discovered by AI-Equipped Security Researcher

ID: 56d6920b-a336-59de-846e-66eea5dc6c68

STIX ID: report--56d6920b-a336-59de-846e-66eea5dc6c68

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2026-05-01

Date Updated: 2026-05-01

...
...

**Copy Fail (CVE-2026-31431)** — A logic bug in the Linux kernel's authenticated encryption template introduced in 2017 allows an unprivileged local user with physical access to trigger a deterministic four‑byte write into the page cache of any readable file, enabling local privilege escalation to root across affected kernels; a proof‑of‑concept exploit has been published, the issue is rated CVSS 7.8, and distributions have released patches that revert the problematic AEAD optimization (update to include commit a664bf3d603d).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.