CISA Adds Actively Exploited Linux Root Access Bug CVE-2026-31431 to KEV
ID: 40b85e56-36f5-51b6-a11d-2588bcaa0646
STIX ID: report--40b85e56-36f5-51b6-a11d-2588bcaa0646
Feed Name: The Hacker News
CISA added a high-severity Linux kernel local privilege escalation vulnerability (CVE-2026-31431, “Copy Fail”, CVSS 7.8) to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. Introduced by historical kernel changes, the flaw lets unprivileged users corrupt the kernel page cache to modify executables at runtime and gain root; PoC exploit code is publicly available in Python/Go/Rust variants. The vulnerability affects distributions shipping kernels since 2017, poses a serious risk to container isolation and cloud environments, and has mitigations in updated kernel versions and vendor patches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
