2026年5月4日星期一

Linux Kernel Elevation of Privilege Vulnerability

Linux Kernel Elevation of Privilege Vulnerability

Release Date: 4 May 2026

RISK: Medium Risk

TYPE: Operating Systems - Linux

A vulnerability was identified in Linux Kernel. A local attacker can exploit this vulnerability to trigger elevation of privilege on the targeted system.

 

Note: 

CVE-2026-31431 is being exploited in the wild. Copy Fail (CVE-2026-31431) is a logic bug in the Linux kernel's authencesn cryptographic template. It lets an unprivileged local user trigger a deterministic, controlled 4-byte write into the page cache of any readable file on the system. A single 732-byte Python script can edit a setuid binary and obtain root on essentially all Linux distributions shipped since 2017.


Impact

  • Elevation of Privilege

System / Technologies affected


Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

沒有留言:

發佈留言

Linux Kernel權限提升漏洞

Linux Kernel權限提升漏洞 發佈日期: 2026年05月04日 風險: 中度風險 類型: 操作系統 - LINUX 於 Linux K...