chiprook
← Security
SecuritySeptember 29, 2026, 08:22

CVE-2026-31431 "Copy Fail": Linux algif_aead privilege escalation explained

A deterministic Linux kernel flaw, CVE-2026-31431 (CVSS 7.8), in crypto/algif_aead.c and authenc_esn.c lets a local user write 4 controlled bytes into the page cache of any readable file and gain root. Introduced in 2017, it affects kernels 4.14–6.18.21 and 6.19.11 and was patched in April 2026.

CVE-2026-31431 "Copy Fail": Linux algif_aead privilege escalation explained
#Linux
Read next
Security

CVE-2026-32996: Privilege Escalation in Veeam Agent for Windows

Security

Public PoC Exposes Critical Veeam Agent Privilege Escalation

Security

ZcopyReaper: A Local Privilege Escalation in the Linux Kernel RDS Path

Security

Microsoft patches CVSS 10.0 Azure AI Foundry flaw enabling privilege escalation