logo

CISA Adds Actively Exploited Linux Root Access Bug CVE-2026-31431 to KEV

ID: 40b85e56-36f5-51b6-a11d-2588bcaa0646

STIX ID: report--40b85e56-36f5-51b6-a11d-2588bcaa0646

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-05-03

Date Updated: 2026-05-03

Author: [email protected] (The Hacker News)

...
...

CISA added a high-severity Linux kernel local privilege escalation vulnerability (CVE-2026-31431, “Copy Fail”, CVSS 7.8) to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. Introduced by historical kernel changes, the flaw lets unprivileged users corrupt the kernel page cache to modify executables at runtime and gain root; PoC exploit code is publicly available in Python/Go/Rust variants. The vulnerability affects distributions shipping kernels since 2017, poses a serious risk to container isolation and cloud environments, and has mitigations in updated kernel versions and vendor patches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.