2026年5月6日星期三

Debian Linux Kernel Multiple Vulnerabilities

Debian Linux Kernel Multiple Vulnerabilities

Release Date: 6 May 2026

RISK: Medium Risk

TYPE: Operating Systems - Linux

Multiple vulnerabilities were identified in Debian Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege and sensitive information disclosure on the targeted system.

 

Note: 

CVE-2026-31431 is being exploited in the wild. Copy Fail (CVE-2026-31431) is a logic bug in the Linux kernel's authencesn cryptographic template. It lets an unprivileged local user trigger a deterministic, controlled 4-byte write into the page cache of any readable file on the system. A single 732-byte Python script can edit a setuid binary and obtain root on essentially all Linux distributions shipped since 2017.


Impact

  • Denial of Service
  • Information Disclosure
  • Elevation of Privilege

System / Technologies affected

  • Debian bookworm versions prior to 6.1.170-1

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

沒有留言:

發佈留言

Fortinet 產品遠端執行程式碼漏洞

Fortinet 產品遠端執行程式碼漏洞 發佈日期 : 2026 年 10 月 02 日 於 Fortinet 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼及資料篡改。   注意: CVE-2025-25249 正在被廣泛利用...