The Lab · 2026-05-02 09:54:06 · GitHub Issues
A critical Linux kernel privilege-escalation vulnerability has left a cluster of production NixOS servers exposed while the necessary security patch remains absent from the stable release branch. CVE-2026-31431, dubbed "Copy Fail," targets the AF_ALG AEAD interface and enables any local user to escalate to root using a...
The Lab · 2026-05-05 05:31:42 · GitHub Issues
A GitHub pull request within the tetragon/example repository introduces a security policy designed to mitigate exploitation of CVE-2026-31431, a disclosed vulnerability. The proposed mitigation operates at the syscall level, intercepting attempts to create AF_ALG sockets—kernel-level cryptographic interfaces—by overrid...
The Lab · 2026-05-08 18:24:41 · Unit 42
Security researchers at Unit 42 have disclosed a critical Linux kernel local privilege escalation vulnerability, designated CVE-2026-31431 and internally named "Copy Fail," which grants attackers stealthy root access to affected systems. The flaw, classified as critical severity, is being described as one of the most s...
The Lab · 2026-05-09 21:01:40 · Hacker News
A newly disclosed Linux kernel vulnerability, catalogued as CVE-2026-43284 and dubbed "Dirty Frag," marks the second local privilege escalation exploit capable of granting root access to emerge within an eight-day window, raising fresh questions about the security posture of widely-deployed Linux kernel versions.
The ...
The Lab · 2026-05-10 18:31:42 · r/netsec
Security researchers have demonstrated a novel technique leveraging Large Language Models to identify critical remote Linux kernel out-of-bounds (OOB) write vulnerabilities, uncovering multiple high-severity flaws including CVE-2026-31432 and CVE-2026-31433. The approach involves strategically perturbing LLM outputs to...
The Lab · 2026-05-11 08:10:35 · GitHub Issues
A high-severity local privilege escalation vulnerability in the Linux kernel's `algif_aead` module has been flagged under active exploitation, prompting urgent inclusion in the CISA Known Exploited Vulnerabilities catalog. Tracked as CVE-2026-31431 with a CVSS score of 7.8, the flaw allows an unprivileged local user to...
The Lab · 2026-05-11 13:40:33 · Mastodon:mastodon.social:#infosec
Security researchers have disclosed a pair of long-dormant Linux kernel vulnerabilities, collectively dubbed "Dirty Frag," that remained hidden in open-source codebases for approximately nine years before being identified. The flaws, linked to memory fragmentation handling in the kernel, represent a significant exposur...
The Lab · 2026-05-11 14:40:31 · Browser The Record
A second critical vulnerability in the Linux kernel has emerged just weeks after the disclosure of the "Copy Fail" flaw, raising fresh concerns about systemic weaknesses in the operating system that underpins the global cloud infrastructure. The new flaw, nicknamed "Dirty Frag," was discovered by independent security r...
The Lab · 2026-05-13 19:48:25 · GitHub Issues
Three Linux kernel local privilege escalation vulnerabilities targeting auto-loadable modules were disclosed in rapid succession between late April and mid-May 2026, raising concerns about container escape risks in Azure Kubernetes Service environments. The flaws share a common attack vector: kernel modules that can be...