2026年5月6日星期三

Debian Linux Kernel Multiple Vulnerabilities

Debian Linux Kernel Multiple Vulnerabilities

Release Date: 6 May 2026

RISK: Medium Risk

TYPE: Operating Systems - Linux

Multiple vulnerabilities were identified in Debian Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege and sensitive information disclosure on the targeted system.

 

Note: 

CVE-2026-31431 is being exploited in the wild. Copy Fail (CVE-2026-31431) is a logic bug in the Linux kernel's authencesn cryptographic template. It lets an unprivileged local user trigger a deterministic, controlled 4-byte write into the page cache of any readable file on the system. A single 732-byte Python script can edit a setuid binary and obtain root on essentially all Linux distributions shipped since 2017.


Impact

  • Denial of Service
  • Information Disclosure
  • Elevation of Privilege

System / Technologies affected

  • Debian bookworm versions prior to 6.1.170-1

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

沒有留言:

發佈留言

Debian Linux 內核多個漏洞

Debian Linux 內核多個漏洞 發佈日期: 2026年05月06日 風險: 中度風險 類型: 操作系統 - LINUX 於 Debian...