Nine-Year-Old Zero-Day Flaw in Linux Kernel Discovered by AI-Equipped Security Researcher
ID: 56d6920b-a336-59de-846e-66eea5dc6c68
STIX ID: report--56d6920b-a336-59de-846e-66eea5dc6c68
Feed Name: Infosecurity Magazine (News)
**Copy Fail (CVE-2026-31431)** — A logic bug in the Linux kernel's authenticated encryption template introduced in 2017 allows an unprivileged local user with physical access to trigger a deterministic four‑byte write into the page cache of any readable file, enabling local privilege escalation to root across affected kernels; a proof‑of‑concept exploit has been published, the issue is rated CVSS 7.8, and distributions have released patches that revert the problematic AEAD optimization (update to include commit a664bf3d603d).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
