Phone Sales & Support 1300 551 084

Phone Sales & Support 1300 551 084

Security Advisory: CVE-2026-31431 (Copy Fail) - Kernel-Level Vulnerability Affecting Linux Servers

  • Sunday, 3rd May, 2026
  • 10:14am

A vulnerability (CVE-2026-31431) affecting the Linux Kernel has been discovered within the the algif_aead optimisation added in the Linux kernel in 2017, this is not tied to a specific distribution but for most kernels. Linux kernels since approximately 2017 (starting around version 4.14) are affected, depending on whether the vulnerable code is present. This affects the underlying operating system kernel.

For Kernels since 2017 that contain an optimisation for the  AF_ALG crypto API. It is possible for a local user to obtain root level access to a Linux server by modifying the page cache the kernel reads when it loads a binary. This is a logical bug that allows users to gain unauthorised root access to a Linux server.

Most Linux distributions as of 03-05-2026 have released a kernel update for test repos over the last 24 hours.  Customers are advised to update their kernel by following instructions for the installed distribution.  Customers can reach out to Entity Data Support for assistance.  Customers with the High Care or Critical Care SLA will receive support priority.

AlmaLinux: https://almalinux.org/blog/2026-05-01-cve-2026-31431-copy-fail/
CloudLinux: https://blog.cloudlinux.com/cve-2026-31431-copy-fail-kernel-update 
Debian: https://security-tracker.debian.org/tracker/CVE-2026-31431
Red Hat Enterprise Linux: https://access.redhat.com/security/vulnerabilities/RHSB-2026-02
Rocky Linux: https://kb.ciq.com/article/rocky-linux/rl-cve-2026-31431-mitigation
Ubuntu: https://ubuntu.com/security/CVE-2026-31431

« Back