2026年5月4日星期一

QNAP NAS Elevation of Privilege Vulnerability

QNAP NAS Elevation of Privilege Vulnerability

Release Date: 4 May 2026

RISK: Medium Risk

TYPE: Servers - Other Servers

A vulnerability was identified in QNAP NAS. A local attacker can exploit this vulnerability to trigger elevation of privilege on the targeted system.

 

Note: 

CVE-2026-31431 is being exploited in the wild. A local privilege escalation vulnerability, commonly known as "Copy Fail", has been reported to affect the Linux kernel. If exploited, this vulnerability could allow an authenticated, non-administrator user with code execution capabilities to obtain elevated system privileges.


Impact

  • Elevation of Privilege

System / Technologies affected

  • QTS on specific QNAP ARM64 NAS models running Kernel 5.10

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

沒有留言:

發佈留言

Linux Kernel權限提升漏洞

Linux Kernel權限提升漏洞 發佈日期: 2026年05月04日 風險: 中度風險 類型: 操作系統 - LINUX 於 Linux K...