Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3192 articles · 168075 vulns · 37/41 feeds (7d)
← Back to list
7.8
CVE-2026-31431KEVEXPLOITEDPATCHED
linux · linux_kernel

crypto: algif_aead - Revert to operating out-of-place

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.

Affected Products

VendorProductVersions
linuxlinux_kernel72548b093ee38a6d4f2a19e6ef1948ae05c181f7, 72548b093ee38a6d4f2a19e6ef1948ae05c181f7, 72548b093ee38a6d4f2a19e6ef1948ae05c181f7, 72548b093ee38a6d4f2a19e6ef1948ae05c181f7, 72548b093ee38a6d4f2a19e6ef1948ae05c181f7, 72548b093ee38a6d4f2a19e6ef1948ae05c181f7, 72548b093ee38a6d4f2a19e6ef1948ae05c181f7, 72548b093ee38a6d4f2a19e6ef1948ae05c181f7, 4.14, 8.3.0.6 and prior, multiple versions, all versions, 5.4, 6.8

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
amazonamazon_linuxcve_cpe95%
aristacloudvision_agnicve_cpe95%
aristacloudvision_portalcve_cpe95%
aristavelocloud_edgecve_cpe95%
aristavelocloud_gatewaycve_cpe95%

References

  • https://git.kernel.org/stable/c/893d22e0135fa394db81df88697fba6032747667
  • https://git.kernel.org/stable/c/19d43105a97be0810edbda875f2cd03f30dc130c
  • https://git.kernel.org/stable/c/961cfa271a918ad4ae452420e7c303149002875b
  • https://git.kernel.org/stable/c/3115af9644c342b356f3f07a4dd1c8905cd9a6fc
  • https://git.kernel.org/stable/c/8b88d99341f139e23bdeb1027a2a3ae10d341d82
  • https://git.kernel.org/stable/c/fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8
  • https://git.kernel.org/stable/c/ce42ee423e58dffa5ec03524054c9d8bfd4f6237
  • https://git.kernel.org/stable/c/a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5

Related News (84 articles)

Tier B
CERT-FR2d ago
Multiples vulnérabilités dans le noyau Linux d'Ubuntu (26 juin 2026)
→ No new info (linked only)
Tier D
The Hacker News18d ago
Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models
→ No new info (linked only)
Tier B
CCCS Canada32d ago
[Control Systems] Moxa security advisory (AV26-509)
→ No new info (linked only)
Tier B
BSI Advisories32d ago
[NEU] [hoch] IBM QRadar SIEM: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
Exploit-DB33d ago
[local] Linux Kernel 6.8 - Local Privilege Escalation
→ No new info (linked only)
Tier B
CCCS Canada38d ago
HPE security advisory (AV26-487)
→ No new info (linked only)
Tier C
oss-security40d ago
CVE-2026-31431 Copy Fail Linux LPE - new public exploit
→ No new info (linked only)
Tier E
Lobsters Security40d ago
Review: Sylve on FreeBSD
→ No new info (linked only)
Tier E
Hacker News43d ago
Show HN: Check for CVE-2026-31431 (copy.fail) without overwriting su
→ No new info (linked only)
Tier B
CERT-FR44d ago
Multiples vulnérabilités dans le noyau Linux de SUSE (15 mai 2026)
→ No new info (linked only)
Tier B
CERT-FR44d ago
Multiples vulnérabilités dans le noyau Linux de Red Hat (15 mai 2026)
→ No new info (linked only)
Tier D
Infosecurity Magazine44d ago
New Fragnesia Flaw Hands Linux Local Users Root Access
→ No new info (linked only)
Tier C
oss-security45d ago
Linux kernel LPE ("fragnesia", copyfail 3.0)
→ No new info (linked only)
Tier E
Reddit r/cybersecurity45d ago
Detecting CopyFail and DirtyFrag by thinking outside the box
→ No new info (linked only)
Tier A
Fortinet PSIRT45d ago
Linux Kernel Vulnerability copy.fail - CVE-2026-31431
→ No new info (linked only)
Tier E
Hacker News46d ago
My implementation of CVE-2026-31431(CopyFail) in C++, no dependency needed
→ No new info (linked only)
Tier C
Schneier on Security46d ago
Copy.Fail Linux Vulnerability
→ No new info (linked only)
Tier D
CSO Online47d ago
Linux kernel maintainers suggest a ‘kill switch’ to protect systems until a zero-day vulnerability is patched
→ No new info (linked only)
Tier D
Infosecurity Magazine47d ago
Rushed Patches Follow Broken Embargo on New Linux Kernel Vulnerabilities
→ No new info (linked only)
Tier E
Hacker News49d ago
The 90 Day disclosure policy is dead
→ No new info (linked only)
Tier E
Hacker News49d ago
"Dirty Frag" (CVE-2026-43284): The Second Linux Root Exploit in Eight Days
→ No new info (linked only)
Tier E
Hacker News49d ago
Dirty Frag: Ongoing Linux Kernel Privilege Escalation Vulnerability Since 2017
→ No new info (linked only)
Tier E
Lobsters Security50d ago
CVE-2026-31431: Copy Fail
→ No new info (linked only)
Tier B
CERT/CC Vuln Notes50d ago
VU#260001: Linux kernel contains local privilege escalation vulnerability (Copy Fail)
→ No new info (linked only)
Tier E
Hacker News50d ago
Dirty Frag (CVE-2026-43284, CVE-2026-43500): Mitigation
→ No new info (linked only)
Tier C
oss-security50d ago
Re: Copy Fail 2 / Dirty Frag — n-day from public commit, not embargo break
→ No new info (linked only)
Tier D
Help Net Security50d ago
May 2026 Patch Tuesday forecast: AI starts driving security industry changes
→ No new info (linked only)
Tier D
The Hacker News50d ago
Linux Kernel Dirty Frag LPE Exploit Enables Root Access Across Major Distributions
→ No new info (linked only)
Tier E
Hacker News51d ago
Cloudflare responded to the "Copy Fail" Linux vulnerability
→ No new info (linked only)
Tier C
oss-security51d ago
Re: Precise disclosure contents for copyfail (Re: [oss-security] CVE-2026-31431: CopyFail: linux local privilege scalation)
→ No new info (linked only)
Tier B
CERT-FR52d ago
Multiples vulnérabilités dans le noyau Linux de SUSE (07 mai 2026)
→ No new info (linked only)
Tier B
CERT-FR52d ago
Multiples vulnérabilités dans le noyau Linux de Red Hat (07 mai 2026)
→ No new info (linked only)
Tier C
oss-security52d ago
Re: CVE-2026-31431: CopyFail: linux local privilege scalation
→ No new info (linked only)
Tier C
Palo Alto Unit 4253d ago
Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years
→ No new info (linked only)
Tier E
Hacker News53d ago
CVE-2026-31431: Copy Fail vs. rootless containers
→ No new info (linked only)
Tier C
oss-security54d ago
Re: Precise disclosure contents for copyfail (Re: [oss-security] CVE-2026-31431: CopyFail: linux local privilege scalation)
→ No new info (linked only)
Tier E
Lobsters Security54d ago
Podman rootless containers and the Copy Fail exploit
→ No new info (linked only)
Tier D
BleepingComputer54d ago
CISA says ‘Copy Fail’ flaw now exploited to root Linux systems
→ No new info (linked only)
Tier D
SecurityWeek54d ago
Exploitation of ‘Copy Fail’ Linux Vulnerability Begins
→ No new info (linked only)
Tier D
Heise Security54d ago
Linux-Lücke „Copy Fail“ wird bereits angegriffen
→ No new info (linked only)
Tier B
CERT-FR55d ago
Multiples vulnérabilités dans les produits Microsoft (04 mai 2026)
→ No new info (linked only)
Tier B
CERT-FR55d ago
Multiples vulnérabilités dans VMware Tanzu Kubernetes Runtime (04 mai 2026)
→ No new info (linked only)
Tier B
CERT-FR55d ago
Vulnérabilité dans Qnap QTS (04 mai 2026)
→ No new info (linked only)
Tier C
oss-security55d ago
Precise disclosure contents for copyfail (Re: [oss-security] CVE-2026-31431: CopyFail: linux local privilege scalation)
→ No new info (linked only)
Tier C
oss-security55d ago
Re: CVE-2026-31431: CopyFail: linux local privilege scalation
→ No new info (linked only)
Tier D
Help Net Security55d ago
Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months
→ No new info (linked only)
Tier D
The Hacker News55d ago
CISA Adds Actively Exploited Linux Root Access Bug CVE-2026-31431 to KEV
→ No new info (linked only)
Tier E
Hacker News56d ago
CISA KEV: Linux "Copy Fail" CVE-2026-31431 Turns Kernel Bug into Patch Deadline
→ No new info (linked only)
Tier C
oss-security56d ago
Re: CVE-2026-31431: CopyFail: linux local privilege scalation
→ No new info (linked only)
Tier C
oss-security57d ago
Re: CVE-2026-31431: CopyFail: linux local privilege scalation
→ No new info (linked only)
Tier C
oss-security57d ago
Re: CVE-2026-31431: CopyFail: linux local privilege scalation
→ No new info (linked only)
Tier C
Rapid7 Blog57d ago
Metasploit Wrap-Up 05/01/2026
→ No new info (linked only)
Tier C
oss-security57d ago
Re: CVE-2026-31431: CopyFail: linux local privilege scalation
→ No new info (linked only)
Tier C
oss-security57d ago
Re: CVE-2026-31431: CopyFail: linux local privilege scalation
→ No new info (linked only)
Tier C
oss-security57d ago
Re: Re: CVE-2026-31431: CopyFail: linux local privilege scalation
→ No new info (linked only)
Tier C
oss-security57d ago
Re: CVE-2026-31431: CopyFail: linux local privilege scalation
→ No new info (linked only)
Tier C
oss-security57d ago
Re: [EXTERNAL] Re: [oss-security] CVE-2026-31431: CopyFail: linux local privilege scalation
→ No new info (linked only)
Tier C
oss-security57d ago
Re: CVE-2026-31431: CopyFail: linux local privilege scalation
→ No new info (linked only)
Tier C
oss-security57d ago
Re: CVE-2026-31431: CopyFail: linux local privilege scalation
→ No new info (linked only)
Tier D
The Record57d ago
Nearly every Linux system built since 2017 vulnerable to ‘Copy Fail’ flaw
→ No new info (linked only)
Tier D
Infosecurity Magazine57d ago
Nine-Year-Old Zero-Day Flaw in Linux Kernel Discovered by AI-Equipped Security Researcher
→ No new info (linked only)
Tier E
Hacker News57d ago
CVE-2026-31431 (Copy Fail): Linux Kernel LPE
→ No new info (linked only)
Tier D
CSO Online57d ago
‘Trivial’ exploit can give attackers root access to Linux kernel
→ No new info (linked only)
Tier D
Ars Technica Security58d ago
The most severe Linux threat to surface in years catches the world flat-footed
→ No new info (linked only)
Tier B
CCCS Canada58d ago
AL26-009 - Vulnerability Affecting Linux - CVE-2026-31431
→ No new info (linked only)
Tier E
Hacker News58d ago
Copy Fail CVE-2026-31431: 732 Bytes to Root on All Linux
→ No new info (linked only)
Tier E
Hacker News58d ago
High Vulnerability in the Linux Kernel ("Copy Fail")
→ No new info (linked only)
Tier E
Hacker News58d ago
Show HN: Copy-fail-C – portable C port of CVE-2026-31431, with a checker
→ No new info (linked only)
Tier D
BleepingComputer58d ago
New Linux ‘Copy Fail’ flaw gives hackers root on major distros
→ No new info (linked only)
Tier E
Hacker News58d ago
CopyFail CVE-2026-31431 mitigation with open source tool
→ No new info (linked only)
Tier D
Help Net Security58d ago
Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431)
→ No new info (linked only)
Tier E
Hacker News58d ago
Detection toolkit for CopyFail(CVE-2026-31431)
→ No new info (linked only)
Tier D
SecurityWeek58d ago
‘Copy Fail’ Logic Flaw in Linux Kernel Enables System Takeover
→ No new info (linked only)
Tier E
Hacker News58d ago
Copy-fail-destroyer: K8s remediation for CVE-2026-31431
→ No new info (linked only)
Tier D
The Hacker News58d ago
New Linux 'Copy Fail' Vulnerability Enables Root Access on Major Distributions
→ No new info (linked only)
Tier D
Heise Security58d ago
„Copy Fail“: Linux-root in allen großen Distributionen mit 732 Byte Python
→ No new info (linked only)
Tier E
Reddit r/cybersecurity59d ago
New critical CVE - Root on Every Major Linux Distribution
→ No new info (linked only)
Tier E
Reddit r/netsec59d ago
Copy Fail exploit lets 732 bytes hijack Linux systems and quietly grab root
→ No new info (linked only)
Tier C
oss-security59d ago
CVE-2026-31431: CopyFail: linux local privilege scalation
→ No new info (linked only)
Tier E
Hacker News59d ago
Copy Fail – CVE-2026-31431
→ No new info (linked only)
Tier A
Microsoft MSRC65d ago
CVE-2026-31431 crypto: algif_aead - Revert to operating out-of-place
→ No new info (linked only)
Tier B
BSI Advisories66d ago
[NEU] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service
→ No new info (linked only)
Tier C
VulDB66d ago
CVE-2026-31431 | Linux Kernel up to 6.18.21/6.19.11 crypto algif_aead privilege escalation
→ No new info (linked only)
Tier C
Linux Kernel CVEs66d ago
CVE-2026-31431: crypto: algif_aead - Revert to operating out-of-place
→ No new info (linked only)
CVSS 3.17.8 HIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
1 April 2026
PublishedApr 22, 2026
Last enriched32d agov33
Tags
root privilege escalationLinux kernelCopy Failsystem takeoverlocal privilege escalationDirty Pipe comparisonAI-driven pentestingIncorrect Resource Transfer Between SpheresPrivilege EscalationCVE-2026-31431CopyFailKubernetes escapeKnown Exploited Vulnerabilitiescontainer escapesnapflatpakroot shell accessCISA KEVcontainer breakoutmulti-tenant compromiselateral movementcloudCI/CDKubernetesdeterministic logic flawKubernetes breakoutmulti-tenant host takeoverCI/CD compromisedeprecated AF_ALGDirty FragCopy Fail 2Electric BoogalooCVE-2026-43284CVE-2026-43500Kubernetes Pod Security StandardsRuntimeDefault seccomp profileshared infrastructurekernel LPEFragnesiacopyfail 3.0public exploitGitHub repositoryHPE ArubaNetworkingAirwaveAOS-CXEdgeConnect OrchestratorAnalytics and Location EngineMeridian Asset TrackingLinux Kernel 6.8
Trending Score117🔥
Source articles84
Independent26
Info Completeness12/14
Missing: epss, cwe

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-43284EXPKEV
xfrm: esp: avoid in-place decrypt on shared skb frags
Trending: 112
HIGHCVE-2026-43500EXPKEV
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
Trending: 106
HIGHCVE-2026-46333EXP
ptrace: slightly saner 'get_dumpable()' logic
Trending: 74
HIGHCVE-2026-46300EXP
net: skbuff: preserve shared-frag marker during coalescing
Trending: 64
HIGHCVE-2026-43503EXP
net: skbuff: propagate shared-frag marker through frag-transfer helpers
Trending: 57

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 22, 2026
Added to CISA KEV
Apr 22, 2026
Discovered by ZDM
Apr 22, 2026
Updated: description, severity, affectedVersions
Apr 22, 2026
Updated: description, exploitAvailable, activelyExploited
Apr 29, 2026
Updated: affectedVersions, iocs, tags
Apr 30, 2026
Updated: description, cweIds, mitreAttack, tags
Apr 30, 2026
Updated: description, affectedVersions, tags
Apr 30, 2026
Updated: description, cweIds, mitreAttack, tags
Apr 30, 2026
Updated: description, affectedVersions, tags
Apr 30, 2026
Updated: cweIds, tags
Apr 30, 2026
Updated: affectedVersions, cweIds, tags
Apr 30, 2026
Updated: description, affectedVersions, cweIds, tags
May 1, 2026
Updated: description
May 1, 2026
Updated: description, affectedVersions
May 1, 2026
Updated: description, cweIds
May 1, 2026
Updated: tags, mitreAttack
May 1, 2026
Updated: description, affectedVersions
May 1, 2026
Updated: description, tags, cweIds
May 1, 2026
Updated: description, cweIds
May 1, 2026
Updated: affectedVersions, tags
May 4, 2026
Updated: description, cweIds
May 4, 2026
Updated: description, affectedVersions, tags
May 5, 2026
Updated: description, tags
May 6, 2026
Updated: tags
May 8, 2026
Updated: tags
May 8, 2026
Updated: affectedVersions, description
May 8, 2026
Updated: cweIds, tags
May 11, 2026
Updated: description, affectedVersions, cweIds
May 12, 2026
Updated: description, patchAvailable, tags
May 12, 2026
Updated: description, tags
May 13, 2026
Updated: tags, mitreAttack
May 13, 2026
Updated: iocs, tags
May 18, 2026
Actively Exploited
May 18, 2026
Exploit Available
May 18, 2026
Patch Available
May 18, 2026
Updated: affectedVersions, tags
May 20, 2026
Updated: affectedVersions, tags
May 26, 2026

Version History

v33
Last enriched 32d ago
v33Tier C32d ago

Added a detailed description of the vulnerability and updated affected versions to include 5.4 and 6.8.

affectedVersionstags
via Exploit-DB
v32Tier B38d ago

Updated vendor to HPE, added new products and affected versions related to CVE-2026-31431.

affectedVersionstags
via CCCS Canada
v31Tier C40d ago

Added a new public exploit repository URL and updated tags to include 'public exploit' and 'GitHub repository'.

iocstags
via oss-security
v30Tier C45d ago

Updated patch availability to null and added new tag 'copyfail 3.0'.

tagsmitreAttack
via oss-security
v29Tier C45d ago

Updated description with detailed technical information about the Fragnesia exploit and added new tags.

descriptiontags
via oss-security
v28Tier C46d ago

Updated description with detailed technical information and added new tags related to the vulnerability.

descriptionpatchAvailabletags
via Schneier on Security
v27Tier D47d ago

The article provides a more detailed description of the vulnerability's context, including a proposed 'kill switch' mitigation strategy and related CVEs (CVE-2026-43284, CVE-2026-43500), and adds new CWEs, MITRE ATT&CK techniques, and tags.

descriptionaffectedVersionscweIds
via CSO Online
v26Tier D47d ago

Updated description with detailed information about the Dirty Frag vulnerability and added new CWE IDs and tags.

cweIdstags
via Infosecurity Magazine
v25Tier B50d ago

Added affected version 4.17, provided a detailed description of the vulnerability, and updated patch availability to null.

affectedVersionsdescription
via CERT/CC Vuln Notes
v24Tier C50d ago

Added new tags 'Copy Fail 2' and 'Electric Boogaloo'.

tags
via oss-security
v23Tier D50d ago

Updated description with details about the Dirty Frag vulnerability and added new tag 'Dirty Frag'.

tags
via The Hacker News
v22Tier C52d ago

Updated description to include the deprecation of AF_ALG and added a new tag for deprecated AF_ALG.

descriptiontags
via oss-security
v21Tier C53d ago

Updated description with detailed technical information about the Copy Fail vulnerability and added new affected versions and tags.

descriptionaffectedVersionstags
via Palo Alto Unit 42
v20Tier D54d ago

Updated description with details on exploitation and added CWE-20, while noting that no official patches were available at the time of disclosure.

descriptioncweIds
via BleepingComputer
v19Tier D54d ago

Updated description with detailed exploitation information, added affected versions as all Linux distributions since 2017, and included new tags related to exploitation and impact.

affectedVersionstags
via SecurityWeek
v18Tier C57d ago

Updated description with new technical details, added CWE-119, and set patchAvailable to null.

descriptioncweIds
via oss-security
v17Tier C57d ago

Updated description with additional context on potential container escapes and added new tags related to container environments.

descriptiontagscweIds
via oss-security
v16Tier C57d ago

Updated description with details about the Copy Fail logic flaw and added affected versions since 2017.

descriptionaffectedVersions
via Rapid7 Blog
v15Tier C57d ago

Added 'Known Exploited Vulnerabilities' tag and included CISA-KEV in MITRE ATT&CK techniques.

tagsmitreAttack
via oss-security
v14Tier C57d ago

Updated description with details on user action initiating the loading of the algif_aead kernel module and added new CWE and tag.

descriptioncweIds
via oss-security
v13Tier D57d ago

Updated description with detailed technical information and added affected versions including major Linux distributions.

descriptionaffectedVersions
via The Record
v12Tier D57d ago

Updated description with detailed technical information about the Copy Fail vulnerability and specified the patch available.

description
via Infosecurity Magazine
v11Tier D57d ago

Updated description with technical details of the CopyFail vulnerability, added affected version '2017', changed severity to CRITICAL, updated CVSS estimate to 9.8, added CWE-787, added IOC URL, added MITRE ATT&CK technique T1548.002, and added 'Kubernetes escape' tag.

descriptionaffectedVersionscweIdstags
via CSO Online
v10Tier D58d ago

Updated severity to CRITICAL, added new affected versions, and included new CWE and tag 'CopyFail'.

affectedVersionscweIdstags
via Ars Technica Security
v9Tier B58d ago

Added CWE-669 and new relevant tags related to the vulnerability.

cweIdstags
via CCCS Canada
v8Tier D58d ago

Updated description with detailed technical insights, added affected versions, and included new tags related to the vulnerability.

descriptionaffectedVersionstags
via BleepingComputer
v7Tier D58d ago

Updated description with new technical details, added CWE-20, and included new CVE-2026-31431.

descriptioncweIdsmitreAttacktags
via Help Net Security
v6Tier D58d ago

Updated description with detailed technical information about the vulnerability and added new affected versions and tags.

descriptionaffectedVersionstags
via SecurityWeek
v5Tier D58d ago

Updated description with new details, added CWE-20, MITRE ATT&CK technique T1068, and introduced the tag 'Copy Fail'.

descriptioncweIdsmitreAttacktags
via The Hacker News
v4Tier D58d ago

Updated description with details about the 'Copy Fail' vulnerability, added affected versions, and included new tags.

affectedVersionsiocstags
via Heise Security
v3Tier C59d ago

Updated description with details about a local privilege escalation vulnerability and marked it as actively exploited with a working proof of concept.

descriptionexploitAvailableactivelyExploited
via oss-security
v2Tier C66d ago

Updated description with details on privilege escalation and changed severity to CRITICAL.

descriptionseverityaffectedVersions
via VulDB
v166d ago

Initial creation