In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.
| Vendor | Product | Versions |
|---|---|---|
| linux | linux_kernel | 72548b093ee38a6d4f2a19e6ef1948ae05c181f7, 72548b093ee38a6d4f2a19e6ef1948ae05c181f7, 72548b093ee38a6d4f2a19e6ef1948ae05c181f7, 72548b093ee38a6d4f2a19e6ef1948ae05c181f7, 72548b093ee38a6d4f2a19e6ef1948ae05c181f7, 72548b093ee38a6d4f2a19e6ef1948ae05c181f7, 72548b093ee38a6d4f2a19e6ef1948ae05c181f7, 72548b093ee38a6d4f2a19e6ef1948ae05c181f7, 4.14, 8.3.0.6 and prior, multiple versions, all versions, 5.4, 6.8 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| amazon | amazon_linux | cve_cpe | 95% |
| arista | cloudvision_agni | cve_cpe | 95% |
| arista | cloudvision_portal | cve_cpe | 95% |
| arista | velocloud_edge | cve_cpe | 95% |
| arista | velocloud_gateway | cve_cpe | 95% |
Added a detailed description of the vulnerability and updated affected versions to include 5.4 and 6.8.
Updated vendor to HPE, added new products and affected versions related to CVE-2026-31431.
Added a new public exploit repository URL and updated tags to include 'public exploit' and 'GitHub repository'.
Updated patch availability to null and added new tag 'copyfail 3.0'.
Updated description with detailed technical information about the Fragnesia exploit and added new tags.
Updated description with detailed technical information and added new tags related to the vulnerability.
The article provides a more detailed description of the vulnerability's context, including a proposed 'kill switch' mitigation strategy and related CVEs (CVE-2026-43284, CVE-2026-43500), and adds new CWEs, MITRE ATT&CK techniques, and tags.
Updated description with detailed information about the Dirty Frag vulnerability and added new CWE IDs and tags.
Added affected version 4.17, provided a detailed description of the vulnerability, and updated patch availability to null.
Added new tags 'Copy Fail 2' and 'Electric Boogaloo'.
Updated description with details about the Dirty Frag vulnerability and added new tag 'Dirty Frag'.
Updated description to include the deprecation of AF_ALG and added a new tag for deprecated AF_ALG.
Updated description with detailed technical information about the Copy Fail vulnerability and added new affected versions and tags.
Updated description with details on exploitation and added CWE-20, while noting that no official patches were available at the time of disclosure.
Updated description with detailed exploitation information, added affected versions as all Linux distributions since 2017, and included new tags related to exploitation and impact.
Updated description with new technical details, added CWE-119, and set patchAvailable to null.
Updated description with additional context on potential container escapes and added new tags related to container environments.
Updated description with details about the Copy Fail logic flaw and added affected versions since 2017.
Added 'Known Exploited Vulnerabilities' tag and included CISA-KEV in MITRE ATT&CK techniques.
Updated description with details on user action initiating the loading of the algif_aead kernel module and added new CWE and tag.
Updated description with detailed technical information and added affected versions including major Linux distributions.
Updated description with detailed technical information about the Copy Fail vulnerability and specified the patch available.
Updated description with technical details of the CopyFail vulnerability, added affected version '2017', changed severity to CRITICAL, updated CVSS estimate to 9.8, added CWE-787, added IOC URL, added MITRE ATT&CK technique T1548.002, and added 'Kubernetes escape' tag.
Updated severity to CRITICAL, added new affected versions, and included new CWE and tag 'CopyFail'.
Added CWE-669 and new relevant tags related to the vulnerability.
Updated description with detailed technical insights, added affected versions, and included new tags related to the vulnerability.
Updated description with new technical details, added CWE-20, and included new CVE-2026-31431.
Updated description with detailed technical information about the vulnerability and added new affected versions and tags.
Updated description with new details, added CWE-20, MITRE ATT&CK technique T1068, and introduced the tag 'Copy Fail'.
Updated description with details about the 'Copy Fail' vulnerability, added affected versions, and included new tags.
Updated description with details about a local privilege escalation vulnerability and marked it as actively exploited with a working proof of concept.
Updated description with details on privilege escalation and changed severity to CRITICAL.
Initial creation