2026年5月4日星期一

Linux Kernel Elevation of Privilege Vulnerability

Linux Kernel Elevation of Privilege Vulnerability

Release Date: 4 May 2026

RISK: Medium Risk

TYPE: Operating Systems - Linux

A vulnerability was identified in Linux Kernel. A local attacker can exploit this vulnerability to trigger elevation of privilege on the targeted system.

 

Note: 

CVE-2026-31431 is being exploited in the wild. Copy Fail (CVE-2026-31431) is a logic bug in the Linux kernel's authencesn cryptographic template. It lets an unprivileged local user trigger a deterministic, controlled 4-byte write into the page cache of any readable file on the system. A single 732-byte Python script can edit a setuid binary and obtain root on essentially all Linux distributions shipped since 2017.


Impact

  • Elevation of Privilege

System / Technologies affected


Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

沒有留言:

發佈留言

Palo Alto 產品多個漏洞

Palo Alto 產品多個漏洞 發佈日期: 2026年08月14日 於 Palo Alto 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升、繞過保安限制、敏感資料洩露、遠端執行任意程式碼及資料篡改。 影響 資料洩露 遠端執行程式碼 篡改 權限提升 繞過保安限...