In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.
https://cert-portal.siemens.com/productcert/html/ssa-328642.html
https://cert-portal.siemens.com/productcert/html/ssa-019113.html
https://securelist.com/vulnerabilities-and-exploits-in-q2-2026/121091/
https://thehackernews.com/2026/07/hacker-runs-hermes-ai-agent-unattended.html
https://thehackernews.com/2026/07/15-year-old-ghostlock-flaw-enables-root.html
https://thehackernews.com/2026/07/new-bad-epoll-linux-kernel-flaw-lets.html
https://thehackernews.com/2026/05/linux-kernel-dirty-frag-lpe-exploit.html
https://www.securityweek.com/ics-patch-tuesday-schneider-electric-siemens-fix-critical-flaws/
https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-02
https://thehackernews.com/2026/06/new-dirtyclone-linux-kernel-flaw-lets.html
https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-06
https://www.infosecurity-magazine.com/news/fragnesia-linux-kernel-lpe-root/
https://aws.amazon.com/security/security-bulletins/rss/2026-030-aws/
https://aws.amazon.com/security/security-bulletins/rss/2026-029-aws/
https://www.infosecurity-magazine.com/news/dirty-frag-linux-kernel/
https://www.databreachtoday.com/dirty-frag-gives-root-on-linux-distros-a-31641
https://kb.cert.org/vuls/id/260001
https://isc.sans.edu/diary/rss/32968
https://aws.amazon.com/security/security-bulletins/rss/2026-027-aws/
https://aws.amazon.com/security/security-bulletins/rss/2026-026-aws/
https://github.com/silentbyte69/copy-fail-CVE-2026-31431-cpp
https://github.com/Daya0x7F0X/cve-research-lab
https://github.com/Hz-zH299/cve-reproduce-reports
https://github.com/thesungod07/CVE-List
https://github.com/HackSpeak/linux-lpe-2026
https://github.com/joaocalciolari07/copyfail-guard
https://github.com/bingyu-83/cve-feishu-bot
https://github.com/pullrun/pullrun
https://github.com/bahartanir/wp2shell-scanner
https://github.com/the-artist111/NeuralReaper
https://github.com/HYCQAQ/Logitech-G-Cloud-GhostLock-CVE-2026-43499
https://github.com/OleksandrBlack/cve_centos
https://github.com/Tinnci/cve-2024-31317
https://github.com/Quaerendir/linux-pagecache-cve-audit
https://github.com/Quaerendir/cve-2026-46331-audit
https://github.com/Hector-Abarca/realrisk-checks
https://github.com/kinryulabs/rootpacket-cve-2026-31431
https://github.com/qux-bbb/CVE_exp
https://github.com/vk-cs/linux-cve-checker
https://github.com/MillerDetach/poc-lab-pro
https://github.com/liamromanis101/k8s-container-escape-audit-lite
https://github.com/SmashMythAmp/poc-lab-605
https://github.com/antinest/CVEs
https://github.com/1neptune/CopyFail
https://github.com/attaattaatta/cve_2026_frag_family_fix
https://github.com/vishvacyber/Detection-Tool-Kit-for-CVE-2026-31431
https://github.com/rain-fly/linux-privesc-cves
https://github.com/Jacob-xiaoping/CVE
https://github.com/huuvehcie/Copy-Fail-CVEs
https://github.com/Iamliuxiaozhen/copy_fail
https://github.com/AtlasVector/Dirty-Frag-CVE-2026-43284
https://github.com/InnerWarden/innerwarden-lab
https://github.com/ridhinva/copyfail-checker
https://github.com/nb-dog/cves
https://github.com/waltrone1/copyfail-safe-check
https://github.com/krislamo/vulnlab
https://github.com/erlangparasu/mitigate_cve_2026_31431-sh
https://github.com/PandaInRed/redos-kernel-cve-patches
https://github.com/yangh-beep/CVE-2026-31431-C
https://github.com/sgkdev/ptrace_may_dream
https://github.com/GubiczaP/cve-2026-31431-checker
https://github.com/cj667113/OCI-Ansible-Fix-CVE-2026-31431
https://github.com/First-John/cve_2026_frag_family_fix
https://github.com/First-John/CVE-2026-43500
https://github.com/Yakovyakov/cve-2026-31431-mitigation
https://github.com/Ruby570bocadito/CVE-ubuntu-server-24.04
https://github.com/fearlessresponsesolution/cve-pocs
https://github.com/royayub/CVE-2026-31431
https://github.com/hershate/CVE-Lookup-skill
https://github.com/insomnisec/public_cve_detections
https://github.com/Pithase/asm-copyfail
https://github.com/Aurillium/public-passwd
https://github.com/Maxime288/CVE-2026-31431-Copy-Fail-R-pertoire-de-Pr-vention
https://github.com/adityasingh108/CVE-2026-31431-Metasploit-exploit
https://github.com/barmi/cve-patch-auditor
https://github.com/xd20111/CVE-2026-43284
https://github.com/PR1N5/CVEVault
https://github.com/dotPY-hax/CopyFail
https://github.com/adibirzu/oci-emergency-patcher
https://github.com/rituraj-dubey/Exploit-POC
https://github.com/Sebastian294/cve-2026-31431
https://github.com/Carlys17/security-scripts
https://github.com/SilverRuler/copy-fail-CVE-2026-31431
https://github.com/thawfeer/exploits
https://github.com/DroPZsec/SplicePrivillegeEscalationFIX
https://github.com/paulorlima9/copyfail-fix
https://github.com/studiogangster/CVE-2026-31431
https://github.com/gbonacini/CVE-2026-31431
https://github.com/polyakovavv/copyfail
https://github.com/dgrobinson0/CopyFile_CVE-2026-31431
https://github.com/blamejs/exceptd-skills
https://github.com/mauricioportela/CVE-2026-31431-Analysis
https://github.com/MaxMerdes/Linux-Kernel-CVE
https://github.com/vorkampfer/copyfail2_electric_boogaloo_fix
https://github.com/linnemanlabs/dirtyfrag-arm64
https://github.com/h1994st/cairn
https://github.com/haydenjames/CVE-2026-31431-check
https://github.com/haydenjames/dirty-frag-check
https://github.com/tuapuikia/linux-security-mitigation
https://github.com/Helios973/CVE-2026-31431_exp.c
https://github.com/Hunt-Benito/copy-fail-cve-2026-31431-linux-kernel-page-cache-lpe
https://github.com/vorkampfer/copy_fail_mitigation
https://github.com/finwo/cve-toolkit
https://github.com/krisiasty/vcheck
https://github.com/hori0729/CVE-2026-31431-Verificador-Exploit
https://github.com/KaraZajac/DIRTYFAIL
https://github.com/yifengzis/CVE
https://github.com/mym0us3r/DIRTY-FRAG-Detection-with-Wazuh-4.14.4
https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag
https://github.com/dixyes/dirtypatch
https://github.com/p401a-ops/Copy-Fail
https://github.com/OpenPixelSystems/c-copy-fail
https://github.com/Morton-Li/copy-fail-CVE-2026-31431
https://github.com/CyberZik/CVE-RESEARCH
https://github.com/hyeonjunjo24/CVE-2026-31431-_Copy-Fail
https://github.com/insomnisec/Detections-CVE-2026-23918
https://github.com/Percivalll/Dirty-Frag-Kubernetes-PoC
https://github.com/guiimoraes/CVE-2026-31431
https://github.com/mk4me/lpe-audit-kit
https://github.com/ClimbMunchkin/fix-cve-2026-3143
https://github.com/julichaan/CVE-2026-31431-python-copyfail-POC
https://github.com/abdelkabirouadoukou/CVE-2026-31431-Analysis-and-Fix
https://github.com/Tecnotec-CL/CVE-2026
https://github.com/tang-yikai/copy-fail-mitigation-with-bpftrace
https://github.com/pvpaulo01/cve-2026-31431
https://github.com/kw-soft/copyfail
https://github.com/Vatson112/deny-af-alg-bpf
https://github.com/361way/CVE-2026-31431
https://github.com/Mr-bv/Copy-fail-CVE-2026-31431-Exploit-in-C
https://github.com/0xploitNinja/Detection-Rules
https://github.com/gagaltotal/cve-2026-31431-copy-fail
https://github.com/ikow/CVE-2026-31431-live-code-corruption
https://github.com/pedro-lucas-melo/Estudo-de-Caso-CVE-2026-31431-CopyFail
https://github.com/StarxSky/CVE-2026-31431
https://github.com/hans362/CVE-2026-31431-Copy-Fail-Container-Escape
https://github.com/grabesec/XCP_ng_CVE-2026-31431_tester
https://github.com/0xN7y/CVE-2026-31431
https://github.com/tangjie1/CVE-2026-31431-Check
https://github.com/luoqianlin/copyfail-c
https://github.com/voxcia-io/copy-fail
https://github.com/OneDemobird/copy-fail-CVE-2026-31431-pythonlower3.10
Published: 2026-04-22
Updated: 2026-09-08
Named Vulnerability: copy.failNamed Vulnerability: CopyFailNamed Vulnerability: Copy FailKnown Exploited Vulnerability (KEV)
Base Score: 6.8
Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C
Severity: Medium
Base Score: 7.8
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity: High
Base Score: 8.6
Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Severity: High
EPSS: 0.99907
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability of Interest