7.8 CVE-2026-31431

Enriched by CISA CISA Kev Catalog Patch Exploit
 

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.
https://nvd.nist.gov/vuln/detail/CVE-2026-31431

Categories

CWE-669 : Incorrect Resource Transfer Between Spheres
The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource. Chain: router's firmware update procedure uses curl with "-k" (insecure) option that disables certificate validation (CWE-295), allowing adversary-in-the-middle (AITM) compromise with a malicious firmware image (CWE-494). PHP-based FAQ management app does not check the MIME type for uploaded images Some image editors modify a JPEG image, but the original EXIF thumbnail image is left intact within the JPEG. (Also an interaction error).

References

0b142b55-0307-4c5a-b3c9-f314f3fb7c5e

134c704f-9b21-4f2e-91b3-4a467353bcc0 Patch Exploit

416baaa9-dc9f-4396-8d5f-8c081fb06d67 Patch Exploit

af854a3a-2127-422b-91ae-364da2661108 Patch Exploit

http://www.openwall.com/lists/oss-security/2026/04/29/23
Exploit Mailing List Patch
http://www.openwall.com/lists/oss-security/2026/04/29/25
Mailing List Patch
http://www.openwall.com/lists/oss-security/2026/04/29/26
Exploit Mailing List Patch
http://www.openwall.com/lists/oss-security/2026/04/30/10
Mailing List Patch
http://www.openwall.com/lists/oss-security/2026/04/30/11
Mailing List Patch
http://www.openwall.com/lists/oss-security/2026/04/30/12
Mailing List Patch
http://www.openwall.com/lists/oss-security/2026/04/30/14
Mailing List Patch
http://www.openwall.com/lists/oss-security/2026/04/30/15
Mailing List Patch
http://www.openwall.com/lists/oss-security/2026/04/30/16
Mailing List Patch
http://www.openwall.com/lists/oss-security/2026/04/30/17
Mailing List
http://www.openwall.com/lists/oss-security/2026/04/30/18
Exploit Mailing List
http://www.openwall.com/lists/oss-security/2026/04/30/2
Mailing List
http://www.openwall.com/lists/oss-security/2026/04/30/20
Mailing List
http://www.openwall.com/lists/oss-security/2026/04/30/5
Exploit Mailing List Patch
http://www.openwall.com/lists/oss-security/2026/04/30/6
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/01/10
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/01/12
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/01/15
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/01/16
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/01/17
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/01/18
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/01/2
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/01/22
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/01/23
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/01/24
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/01/3
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/02/14
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/02/15
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/02/16
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/02/17
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/02/18
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/02/19
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/02/20
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/02/21
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/02/23
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/02/24
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/02/25
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/02/4
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/02/5
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/02/6
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/02/7
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/02/8
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/03/10
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/03/12
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/03/13
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/03/3
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/03/4
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/03/5
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/03/6
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/04/1
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/04/10
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/04/11
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/04/12
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/04/13
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/04/14
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/04/2
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/04/24
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/04/27
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/04/28
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/04/29
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/04/31
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/04/8
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/04/9
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/06/5
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/07/12
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/07/2
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/08/13
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/18/3
Mailing List
https://copy.fail
Exploit
https://websec.net/blog/cve-2026-31431-linux-algifaead-page-cache-write-to-ro...
Exploit Third Party Advisory
https://www.kb.cert.org/vuls/id/260001
Third Party Advisory


 

AFFECTED (from MITRE)


Vendor Product Versions
Linux Linux
  • 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 < 893d22e0135fa394db81df88697fba6032747667 [affected]
  • 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 < 19d43105a97be0810edbda875f2cd03f30dc130c [affected]
  • 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 < 961cfa271a918ad4ae452420e7c303149002875b [affected]
  • 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 < 3115af9644c342b356f3f07a4dd1c8905cd9a6fc [affected]
  • 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 < 8b88d99341f139e23bdeb1027a2a3ae10d341d82 [affected]
  • 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 < fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8 [affected]
  • 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 < ce42ee423e58dffa5ec03524054c9d8bfd4f6237 [affected]
  • 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 < a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5 [affected]
Linux Linux
  • 4.14 [affected]
  • < 4.14 [unaffected]
  • 5.10.254 ≤ 5.10.* [unaffected]
  • 5.15.204 ≤ 5.15.* [unaffected]
  • 6.1.170 ≤ 6.1.* [unaffected]
  • 6.6.137 ≤ 6.6.* [unaffected]
  • 6.12.85 ≤ 6.12.* [unaffected]
  • 6.18.22 ≤ 6.18.* [unaffected]
  • 6.19.12 ≤ 6.19.* [unaffected]
  • 7.0 ≤ * [unaffected]
© 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

CPE

cpe start end
Configuration 1
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* >= 4.14 < 5.10.254
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* >= 5.11 < 5.15.204
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* >= 5.16 < 6.1.170
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* >= 6.2 < 6.6.137
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* >= 6.7 < 6.12.85
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* >= 6.13 < 6.18.22
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* >= 6.19 < 6.19.12
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:*
Configuration 2
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.1:*:*:*:*:*:*:*
Configuration 3
cpe:2.3:o:amazon:amazon_linux:-:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:-:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:13.0:*:*:*:*:*:*:*
Configuration 4
cpe:2.3:o:opensuse:leap:15.3:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:15.4:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:15.5:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:15.6:*:*:*:*:*:*:*
Configuration 5
cpe:2.3:a:suse:caas_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:a:suse:enterprise_storage:6.0:*:*:*:*:*:*:*
cpe:2.3:a:suse:enterprise_storage:7.0:*:*:*:*:*:*:*
cpe:2.3:a:suse:enterprise_storage:7.1:*:*:*:*:*:*:*
cpe:2.3:a:suse:manager_proxy:4.0:*:*:*:*:*:*:*
cpe:2.3:a:suse:manager_proxy:4.1:*:*:*:*:*:*:*
cpe:2.3:a:suse:manager_proxy:4.2:*:*:*:*:*:*:*
cpe:2.3:a:suse:manager_proxy:4.3:*:*:*:*:*:*:*
cpe:2.3:a:suse:manager_retail_branch_server:4.0:*:*:*:*:*:*:*
cpe:2.3:a:suse:manager_retail_branch_server:4.1:*:*:*:*:*:*:*
cpe:2.3:a:suse:manager_retail_branch_server:4.2:*:*:*:*:*:*:*
cpe:2.3:a:suse:manager_retail_branch_server:4.3:*:*:*:*:*:*:*
cpe:2.3:a:suse:manager_server:4.0:*:*:*:*:*:*:*
cpe:2.3:a:suse:manager_server:4.1:*:*:*:*:*:*:*
cpe:2.3:a:suse:manager_server:4.2:*:*:*:*:*:*:*
cpe:2.3:a:suse:manager_server:4.3:*:*:*:*:*:*:*
cpe:2.3:a:suse:openstack_cloud:9.0:*:*:*:*:*:*:*
cpe:2.3:a:suse:openstack_cloud_crowbar:9.0:*:*:*:*:*:*:*
Configuration 6
cpe:2.3:o:suse:basesystem_module:15:sp1:*:*:*:suse_linux_enterprise:*:*
cpe:2.3:o:suse:basesystem_module:15:sp2:*:*:*:suse_linux_enterprise:*:*
cpe:2.3:o:suse:basesystem_module:15:sp3:*:*:*:suse_linux_enterprise:*:*
cpe:2.3:o:suse:basesystem_module:15:sp4:*:*:*:suse_linux_enterprise:*:*
cpe:2.3:o:suse:basesystem_module:15:sp5:*:*:*:suse_linux_enterprise:*:*
cpe:2.3:o:suse:basesystem_module:15:sp6:*:*:*:suse_linux_enterprise:*:*
cpe:2.3:o:suse:basesystem_module:15:sp7:*:*:*:suse_linux_enterprise:*:*
cpe:2.3:o:suse:development_tools_module:15:sp1:*:*:*:suse_linux_enterprise:*:*
cpe:2.3:o:suse:development_tools_module:15:sp2:*:*:*:suse_linux_enterprise:*:*
cpe:2.3:o:suse:development_tools_module:15:sp3:*:*:*:suse_linux_enterprise:*:*
cpe:2.3:o:suse:development_tools_module:15:sp4:*:*:*:suse_linux_enterprise:*:*
cpe:2.3:o:suse:development_tools_module:15:sp5:*:*:*:suse_linux_enterprise:*:*
cpe:2.3:o:suse:development_tools_module:15:sp6:*:*:*:suse_linux_enterprise:*:*
cpe:2.3:o:suse:development_tools_module:15:sp7:*:*:*:suse_linux_enterprise:*:*
cpe:2.3:o:suse:legacy_module:15:sp7:*:*:*:suse_linux_enterprise:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:11:sp4:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:12:sp4:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:15:sp1:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:15:sp2:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:15:sp3:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:15:sp4:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:15:sp5:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:15:sp6:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:15:sp7:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_high_availability_extension:15:sp4:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_high_availability_extension:15:sp6:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_high_availability_extension:15:sp7:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_high_availability_extension:16.0:-:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_high_performance_computing:15.0:sp1:*:*:-:*:*:*
cpe:2.3:o:suse:linux_enterprise_high_performance_computing:15.0:sp1:*:*:espos:*:*:*
cpe:2.3:o:suse:linux_enterprise_high_performance_computing:15.0:sp1:*:*:ltss:*:*:*
cpe:2.3:o:suse:linux_enterprise_high_performance_computing:15.0:sp2:*:*:-:*:*:*
cpe:2.3:o:suse:linux_enterprise_high_performance_computing:15.0:sp2:*:*:espos:*:*:*
cpe:2.3:o:suse:linux_enterprise_high_performance_computing:15.0:sp2:*:*:ltss:*:*:*
cpe:2.3:o:suse:linux_enterprise_high_performance_computing:15.0:sp3:*:*:-:*:*:*
cpe:2.3:o:suse:linux_enterprise_high_performance_computing:15.0:sp3:*:*:espos:*:*:*
cpe:2.3:o:suse:linux_enterprise_high_performance_computing:15.0:sp3:*:*:ltss:*:*:*
cpe:2.3:o:suse:linux_enterprise_high_performance_computing:15.0:sp4:*:*:-:*:*:*
cpe:2.3:o:suse:linux_enterprise_high_performance_computing:15.0:sp4:*:*:espos:*:*:*
cpe:2.3:o:suse:linux_enterprise_high_performance_computing:15.0:sp4:*:*:ltss:*:*:*
cpe:2.3:o:suse:linux_enterprise_high_performance_computing:15.0:sp5:*:*:-:*:*:*
cpe:2.3:o:suse:linux_enterprise_high_performance_computing:15.0:sp5:*:*:espos:*:*:*
cpe:2.3:o:suse:linux_enterprise_high_performance_computing:15.0:sp5:*:*:ltss:*:*:*
cpe:2.3:o:suse:linux_enterprise_high_performance_computing:15.0:sp6:*:*:-:*:*:*
cpe:2.3:o:suse:linux_enterprise_high_performance_computing:15.0:sp7:*:*:-:*:*:*
cpe:2.3:o:suse:linux_enterprise_live_patching:12:sp5:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_live_patching:15:sp4:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_live_patching:15:sp5:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_live_patching:15:sp6:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_live_patching:15:sp7:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_micro:5.0:*:*:*:*:-:*:*
cpe:2.3:o:suse:linux_enterprise_micro:5.1:*:*:*:*:-:*:*
cpe:2.3:o:suse:linux_enterprise_micro:5.2:*:*:*:*:-:*:*
cpe:2.3:o:suse:linux_enterprise_micro:5.2:*:*:*:*:rancher:*:*
cpe:2.3:o:suse:linux_enterprise_micro:5.3:*:*:*:*:-:*:*
cpe:2.3:o:suse:linux_enterprise_micro:5.3:*:*:*:*:rancher:*:*
cpe:2.3:o:suse:linux_enterprise_micro:5.4:*:*:*:*:-:*:*
cpe:2.3:o:suse:linux_enterprise_micro:5.4:*:*:*:*:rancher:*:*
cpe:2.3:o:suse:linux_enterprise_micro:5.5:*:*:*:*:-:*:*
cpe:2.3:o:suse:linux_enterprise_real_time:15.0:sp2:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_real_time:15.0:sp3:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_real_time:15.0:sp4:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_real_time:15.0:sp5:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_real_time:15.0:sp6:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_real_time:15.0:sp7:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp4:*:*:-:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp4:*:*:ltss:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp4:*:*:ltss_extreme_core:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:sp4:*:*:-:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:sp4:*:*:-:sap:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:sp4:*:*:espos:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:sp4:*:*:ltss:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:sp5:*:*:-:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:sp5:*:*:ltss:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:sp5:*:*:ltss_extended_security:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:15:sp1:*:*:-:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:15:sp1:*:*:-:sap:*:*
cpe:2.3:o:suse:linux_enterprise_server:15:sp1:*:*:business_critical_linux:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:15:sp1:*:*:ltss:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:15:sp2:*:*:-:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:15:sp2:*:*:-:sap:*:*
cpe:2.3:o:suse:linux_enterprise_server:15:sp2:*:*:business_critical_linux:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:15:sp2:*:*:ltss:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:15:sp3:*:*:-:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:15:sp3:*:*:-:sap:*:*
cpe:2.3:o:suse:linux_enterprise_server:15:sp3:*:*:business_critical_linux:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:15:sp3:*:*:ltss:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:15:sp4:*:*:-:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:15:sp4:*:*:-:sap:*:*
cpe:2.3:o:suse:linux_enterprise_server:15:sp4:*:*:ltss:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:15:sp5:*:*:-:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:15:sp5:*:*:-:sap:*:*
cpe:2.3:o:suse:linux_enterprise_server:15:sp5:*:*:ltss:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:15:sp6:*:*:-:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:15:sp6:*:*:-:sap:*:*
cpe:2.3:o:suse:linux_enterprise_server:15:sp6:*:*:ltss:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:15:sp7:*:*:-:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:15:sp7:*:*:-:sap:*:*
cpe:2.3:o:suse:linux_enterprise_server:16.0:-:*:*:-:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:16.0:-:*:*:-:sap:*:*
cpe:2.3:o:suse:linux_enterprise_server:16.1:-:*:*:-:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:16.1:-:*:*:-:sap:*:*
cpe:2.3:o:suse:linux_enterprise_workstation_extension:15:sp7:*:*:*:*:*:*
cpe:2.3:o:suse:linux_micro:6.0:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_micro:6.1:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_micro:6.2:*:*:*:*:*:*:*
cpe:2.3:o:suse:public_cloud_module:15:sp6:*:*:*:suse_linux_enterprise:*:*
cpe:2.3:o:suse:public_cloud_module:15:sp7:*:*:*:suse_linux_enterprise:*:*
cpe:2.3:o:suse:realtime_module:15:sp3:*:*:*:suse_linux_enterprise:*:*
cpe:2.3:o:suse:realtime_module:15:sp4:*:*:*:suse_linux_enterprise:*:*
cpe:2.3:o:suse:realtime_module:15:sp5:*:*:*:suse_linux_enterprise:*:*
cpe:2.3:o:suse:realtime_module:15:sp6:*:*:*:suse_linux_enterprise:*:*
cpe:2.3:o:suse:realtime_module:15:sp7:*:*:*:suse_linux_enterprise:*:*
Configuration 7
cpe:2.3:o:nixos:nixos:*:*:*:*:*:*:*:* < 25.11
Configuration 8
cpe:2.3:a:arista:cloudvision_agni:*:*:*:*:*:-:*:* >= 2024.4.0 <= 2025.2.2
cpe:2.3:a:arista:cloudvision_portal:*:*:*:*:*:*:*:* >= 2024.2.0 <= 2026.1.0
cpe:2.3:a:arista:velocloud_edge:*:*:*:*:*:*:*:* >= 4.5.0 <= 6.4.1
cpe:2.3:a:arista:velocloud_gateway:-:*:*:*:*:*:*:*
cpe:2.3:a:vmware:velocloud_orchestrator:-:*:*:*:*:*:*:*
cpe:2.3:o:arista:netvisor_os:*:*:*:*:*:*:*:* < 7.1.0
cpe:2.3:o:arista:netvisor_os:7.1.0:-:*:*:*:*:*:*
cpe:2.3:o:arista:netvisor_os:7.1.0:hotfix7:*:*:*:*:*:*
Configuration 9
AND
   cpe:2.3:o:siemens:simatic_s7-1500_cpu_1518-4_pn/dp_mfp_firmware:*:*:*:*:*:*:*:* >= 3.1.5
  Running on/with
  cpe:2.3:h:siemens:simatic_s7-1500_cpu_1518-4_pn/dp_mfp:-:*:*:*:*:*:*:*
Configuration 10
AND
   cpe:2.3:o:siemens:simatic_s7-1500_cpu_1518f-4_pn/dp_mfp_firmware:*:*:*:*:*:*:*:* >= 3.1.5
  Running on/with
  cpe:2.3:h:siemens:simatic_s7-1500_cpu_1518f-4_pn/dp_mfp:-:*:*:*:*:*:*:*
Configuration 11
AND
   cpe:2.3:o:siemens:siplus_s7-1500_cpu_1518-4_pn/dp_mfp_firmware:*:*:*:*:*:*:*:* >= 3.1.5
  Running on/with
  cpe:2.3:h:siemens:siplus_s7-1500_cpu_1518-4_pn/dp_mfp:-:*:*:*:*:*:*:*
Configuration 12
AND
   cpe:2.3:o:siemens:simatic_s7-1500_tm_mfp_firmware:*:*:*:*:*:*:*:* < 1.1
  Running on/with
  cpe:2.3:h:siemens:simatic_s7-1500_tm_mfp:-:*:*:*:*:*:*:*


REMEDIATION


Patch

Url
https://xint.io/blog/copy-fail-linux-distributions#the-fix-6
https://git.kernel.org/stable/c/19d43105a97be0810edbda875f2cd03f30dc130c
https://git.kernel.org/stable/c/3115af9644c342b356f3f07a4dd1c8905cd9a6fc
https://git.kernel.org/stable/c/893d22e0135fa394db81df88697fba6032747667
https://git.kernel.org/stable/c/8b88d99341f139e23bdeb1027a2a3ae10d341d82
https://git.kernel.org/stable/c/961cfa271a918ad4ae452420e7c303149002875b
https://git.kernel.org/stable/c/a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5
https://git.kernel.org/stable/c/ce42ee423e58dffa5ec03524054c9d8bfd4f6237
https://git.kernel.org/stable/c/fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8
http://www.openwall.com/lists/oss-security/2026/04/29/23
http://www.openwall.com/lists/oss-security/2026/04/29/25
http://www.openwall.com/lists/oss-security/2026/04/29/26
http://www.openwall.com/lists/oss-security/2026/04/30/10
http://www.openwall.com/lists/oss-security/2026/04/30/11
http://www.openwall.com/lists/oss-security/2026/04/30/12
http://www.openwall.com/lists/oss-security/2026/04/30/14
http://www.openwall.com/lists/oss-security/2026/04/30/15
http://www.openwall.com/lists/oss-security/2026/04/30/16
http://www.openwall.com/lists/oss-security/2026/04/30/5


EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url
https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431
https://github.com/gubaiovo/CVE-2026-31431
https://github.com/iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail
https://github.com/Y5neKO/copy-fail-CVE-2026-31431-universal
https://github.com/Aurillium/RootRemover
https://github.com/freelabz/CVE-2026-31431
https://github.com/mrowkoob/copy-fail-mitigate-no-reboot
https://github.com/pascal-gujer/CVE-2026-31431
https://github.com/0xBlackash/CVE-2026-31431
https://github.com/H1d3r/copy-fail_LPE_Interactive
https://github.com/amdisrar/cve-2026-31431-mitigation
https://github.com/shadowabi/CVE-2026-31431-CopyFail-Universal-LPE
https://github.com/dicatalin/Copy_Fail_CVE-2026-31431_test_and_fix
https://github.com/wesmar/CVE-2026-31431
https://github.com/MohamedKarrab/Copy-Fail-CVE-2026-31431
https://github.com/w3llr00t3d/CVE-2026-31431-PoC
https://github.com/sec17br/CVE-2026-31431-Copy-Fail
https://github.com/websecnl/CVE-2026-31431
https://github.com/professional-slacker/alg_check
https://github.com/cyber-joker/copy-fail-python
https://github.com/Fulucky0-yuri/CVE-2026-31431-PocC
https://github.com/AliHzSec/CVE-2026-31431
https://github.com/toxy4ny/copy-fail-exploit-on-c-redteam
https://github.com/kvakirsanov/CVE-2026-31431-live-process-code-injection
https://github.com/atgreen/block-copyfail
https://github.com/beatbeast007/Linux-CopyFail-C-Version-CVE-2026-31431
https://github.com/sbeteta42/CVE-2026-31431_je_sappelle_RoOt
https://github.com/rvizx/CVE-2026-31431
https://github.com/ben-slates/CVE-2026-31431-Exploit
https://github.com/sercuritycyber/COPY-FAIL-CVE-2026-31431
https://github.com/bootsareme/copyfail-deconstructed
https://github.com/euriconicacio/copy-fail-CVE-2026-31431-poc
https://github.com/ROSNLR5/modrosnlr5
https://github.com/xd20111/CVE-2026-31431
https://github.com/EynaExp/Copy-Fail-CVE-2026-31431-modernized
https://github.com/Trex1e/copyfail-CVE-2026-31431
https://github.com/KanbaraAkihito/CVE-2026-31431-copyfail-rs
https://github.com/M4xSec/CVE-2026-31431-RCE-Exploit
https://github.com/Sl4cK0TH/CVE-2026-31431-PoC
https://github.com/astounds/copy-fail-CVE-2026-31431
https://github.com/aexdyhaxor/CVE-2026-31431-copy-fail
https://github.com/vyahello/CVE-2026-31431
https://github.com/ChernStepanov/CopyFail-for-dummies
https://github.com/xn0kkx/CVE-2026-31431_CopyFail_LinuxKernel_LPE
https://github.com/samanzamani/copy-fail-checker
https://github.com/vasyapokemon/cve-2026-31431
https://github.com/xeloxa/copyfail-exploit
https://github.com/rippsec/CVE-2026-31431-Copy-Fail
https://github.com/Industri4l-H3ll-Xpl0it3rs/CVE-2026-31431-Copy-Fail
https://github.com/zhanghangorg/cve-2026-31431
https://github.com/zenzue/CVE-2026-31431-Checker-Mitigator
https://github.com/iblamenear/CVE-2026-31431-Copy-Fail---Advanced-LPE-Proof-o...
https://github.com/cx330zer0/CVE-2026-31431-Copy-Fail-add-arm64
https://github.com/Morton-Li/copy-fail-CVE-2026-31431
https://github.com/0xlane/pagecache-guard
https://github.com/ROSNLR5/MitigationToolkit-ROSN-LR5-Full
https://github.com/hori0729/CVE-2026-31431-Verificador-Exploit
https://github.com/Hunt-Benito/copy-fail-cve-2026-31431-linux-kernel-page-cac...
https://github.com/Lutfifakee-Project/CVE-2026-31431
https://github.com/Koshmare-Blossom/Copyfail-sh

Other Nist (github, ...)

Url
https://github.com/theori-io/copy-fail-CVE-2026-31431
https://xint.io/blog/copy-fail-linux-distributions#the-fix-6
http://www.openwall.com/lists/oss-security/2026/04/29/23
http://www.openwall.com/lists/oss-security/2026/04/29/26
http://www.openwall.com/lists/oss-security/2026/04/30/18
http://www.openwall.com/lists/oss-security/2026/04/30/5
https://copy.fail
https://websec.net/blog/cve-2026-31431-linux-algifaead-page-cache-write-to-ro...


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
No entry